Memory leak in the login_user function in saslserv/main.c in saslserv/main.so in Atheme 7.2.7 allows a remote unauthenticated attacker to consume memory and cause a denial of service. This is fixed in 7.2.8.
The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/96552 | vdb entry |
https://github.com/atheme/atheme/releases/tag/v7.2.8 | release notes patch vendor advisory |
https://github.com/atheme/atheme/pull/539 | issue tracking third party advisory patch |