-
-
Notifications
You must be signed in to change notification settings - Fork 11k
Closed
Labels
hold: discussionThe community needs to establish a consensus how to move forward with the issue or PRThe community needs to establish a consensus how to move forward with the issue or PRtriaged: questionThe issue contains a questionThe issue contains a question
Description
These guys found a way to saturate the server CPU core to 100% using as little as 5 KB/s of incoming traffic. The pre-requisite is that the server supports DHE as the key exchange. Therefore, to avoid creating such a vulnerable configuration, I propose removing DHE from the SSL_DEFAULT_CIPHER_LIST or TLS_DEFAULT_CIPHERSUITES.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
hold: discussionThe community needs to establish a consensus how to move forward with the issue or PRThe community needs to establish a consensus how to move forward with the issue or PRtriaged: questionThe issue contains a questionThe issue contains a question