fetchnews in leafnode 1.9.47 and earlier allows remote attackers to cause a denial of service (process hang) via an empty NNTP news article with missing mandatory headers.
Link | Tags |
---|---|
http://www.osvdb.org/3441 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/14189 | vdb entry |
http://secunia.com/advisories/10590 | third party advisory patch |
http://www.derkeiler.com/Mailing-Lists/VulnWatch/2004-01/0009.html | mailing list |
http://leafnode.sourceforge.net/leafnode-SA-2004-01.txt | patch |