PT-2001-1998 · 6Tunnel · 6Tunnel
CVE-2001-0830
·
Publicado
2001-12-06
·
Atualizado
2024-02-09
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
6tunnel versions 0.08 and earlier
Description
The issue allows remote attackers to cause a denial of service, specifically resource exhaustion, by repeatedly connecting to and disconnecting from the server. This is due to the software not properly closing sockets initiated by a client.
Recommendations
For 6tunnel versions 0.08 and earlier, consider updating to a version that properly closes sockets to prevent resource exhaustion. As a temporary workaround, restrict access to the server to minimize the risk of exploitation.
Exploit
Correção
Missing Release of Resource after Effective Lifetime
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
6Tunnel