PT-2007-7394 · Tcpreen · Tcpreen

Published

2007-12-28

·

Updated

2017-08-08

·

CVE-2007-6562

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions TCPreen versions prior to 1.4.4
Description The issue is related to multiple stack-based buffer overflows in the use of FD SET, allowing remote attackers to cause a denial of service via multiple concurrent connections. This results in overflows in the SocketAddress::Connect function in libsolve/sockprot.cpp and the monitor bridge function in src/bridge.cpp.
Recommendations For versions prior to 1.4.4, update to version 1.4.4 or later to resolve the issue. As a temporary workaround, consider restricting the number of concurrent connections to minimize the risk of exploitation.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-6562
DSA-1443-1

Affected Products

Tcpreen