PT-2005-2868 · Leafnode · Leafnode
Publicado
2005-06-08
·
Atualizado
2008-09-05
·
CVE-2005-1911
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
leafnode versions 1.11.2 and earlier
Description
The issue concerns the fetchnews NNTP client, which can hang while waiting for input that never arrives. This allows remote NNTP servers to cause a denial of service, resulting in news loss.
Recommendations
For leafnode versions 1.11.2 and earlier, consider updating to a version later than 1.11.2 to resolve the issue. As a temporary workaround, restrict access to the fetchnews NNTP client to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Leafnode