6tunnel 0.08 and earlier does not properly close sockets that were initiated by a client, which allows remote attackers to cause a denial of service (resource exhaustion) by repeatedly connecting to and disconnecting from the server.
The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=100386451702966&w=2 | exploit mailing list |
http://www.securityfocus.com/bid/3467 | broken link third party advisory vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/7337 | third party advisory vdb entry |
ftp://213.146.38.146/pub/wojtekka/6tunnel-0.09.tar.gz | broken link |