Two vulnerabilities were found in cfservd, a daemon which acts as both a file server and a remote cfagent executor. This daemon authenticates requests from the network and processes them. If exploited, the first vulnerability allows an attacker to execute arbitrary code with those privileges of root. The second vulnerability allows an attacker to crash the server, denying service to further requests.
Kurt this is your baby.
Bumping to 2.1.9 seems to work.
Security : GLSA drafted please review.
Another URL that might be useful in drafting the GLSA:
Committed 2.1.9 directly to stable on x86 after testing it on my machine. As soon as sparc stables it, we're good to go.
Woops Kurt didn't CC sparc.
sparc please mark stable ASAP so the GLSA can go out.
sparc me amadeus
woops closing for Kurt.