PT-2001-1998 · 6Tunnel · 6Tunnel
Published
2001-12-06
·
Updated
2024-02-09
·
CVE-2001-0830
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
6tunnel versions 0.08 and earlier
Description
The issue allows remote attackers to cause a denial of service, specifically resource exhaustion, by repeatedly connecting to and disconnecting from the server. This is due to the software not properly closing sockets initiated by a client.
Recommendations
For 6tunnel versions 0.08 and earlier, consider updating to a version that properly closes sockets to prevent resource exhaustion. As a temporary workaround, restrict access to the server to minimize the risk of exploitation.
Exploit
Fix
Missing Release of Resource after Effective Lifetime
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
6Tunnel