Security never sleeps, even if it is the week between Christmas and New Year’s. Vulnerability discovered yesterday by Alexander Klink and Julian Walde at Chaos Communication Congress. As little as 30k/sec could be necessary to occupy a single i7 core, depending on the target platform. Large numbers of key/value pairs are necessary to trigger bug, and so it’s a matter of counting them up in a given request. We’ve released SIDs 20823 and 20824 in an SEU late last night to cover this vulnerability.”]
Source: https://blog.talosintelligence.com/2011/12/cross-platform-single-request-web.html

