[Last-Call] Secdir last call review of draft-ietf-nfsv4-layoutwcc-04

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Reviewer: Benjamin Schwartz
Review result: Ready

This specification is not highly security-relevant, and it does not have any
content in its Security Considerations.

In general, allowing file metadata, including size and ownership, to be
desynchronized from the file contents, does carry significant security
implications.  For example, understating the size of the file could lead to a
buffer overflow in an incautious client.  If these considerations have already
been addressed in another document, I think a specific citation to that text
would be appropriate here.


-- 
last-call mailing list -- last-call@xxxxxxxx
To unsubscribe send an email to last-call-leave@xxxxxxxx




[Index of Archives]     [IETF Annoucements]     [IETF]     [IP Storage]     [Yosemite News]     [Linux SCTP]     [Linux Newbies]     [Mhonarc]     [Fedora Users]

  Powered by Linux