Vulnerabilities > CVE-2005-1453 - Unspecified vulnerability in Leafnode

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
leafnode
nessus

Summary

fetchnews in leafnode 1.9.48 to 1.11.1 allows remote NNTP servers to cause a denial of service (crash) by closing the connection while fetchnews is reading (1) an article header or (2) an article body, which also prevents fetchnews from querying other servers.

Nessus

  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_PKG_66DBB2EE99B845B2BB3E640CAEA67A60.NASL
    descriptionWhen an upstream server aborts the transmission or stops sending data after the fetchnews program has requested an article header or body, fetchnews may crash, without querying further servers that are configured. This can prevent articles from being fetched.
    last seen2020-06-01
    modified2020-06-02
    plugin id18966
    published2005-07-13
    reporterThis script is Copyright (C) 2005-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/18966
    titleFreeBSD : leafnode -- fetchnews denial-of-service triggered by transmission abort/timeout (66dbb2ee-99b8-45b2-bb3e-640caea67a60)
  • NASL familyMandriva Local Security Checks
    NASL idMANDRAKE_MDKSA-2005-114.NASL
    descriptionA number of vulnerabilities in the leafnode NNTP server package have been found : A vulnerability in the fetchnews program that could under some circumstances cause a wait for input that never arrives, which in turn would cause fetchnews to hang (CVE-2004-2068). Two vulnerabilities in the fetchnews program can cause fetchnews to crash when the upstream server closes the connection and leafnode is receiving an article header or an article body, which prevent leafnode from querying other servers that are listed after that particular server in the configuration file (CVE-2005-1453). Finally, another vulnerability in the fetchnews program could also cuase a wait for input that never arrives, causing fetchnews to hang (CVE-2005-1911). The updated packages have been patched to correct this problem.
    last seen2020-06-01
    modified2020-06-02
    plugin id18676
    published2005-07-12
    reporterThis script is Copyright (C) 2005-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/18676
    titleMandrake Linux Security Advisory : leafnode (MDKSA-2005:114)