Vulnerabilities > CVE-2005-1911 - Unspecified vulnerability in Leafnode

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
leafnode
nessus

Summary

The fetchnews NNTP client in leafnode 1.11.2 and earlier can hang while waiting for input that never arrives, which allows remote NNTP servers to cause a denial of service (news loss).

Nessus

  • NASL familyMandriva Local Security Checks
    NASL idMANDRAKE_MDKSA-2005-114.NASL
    descriptionA number of vulnerabilities in the leafnode NNTP server package have been found : A vulnerability in the fetchnews program that could under some circumstances cause a wait for input that never arrives, which in turn would cause fetchnews to hang (CVE-2004-2068). Two vulnerabilities in the fetchnews program can cause fetchnews to crash when the upstream server closes the connection and leafnode is receiving an article header or an article body, which prevent leafnode from querying other servers that are listed after that particular server in the configuration file (CVE-2005-1453). Finally, another vulnerability in the fetchnews program could also cuase a wait for input that never arrives, causing fetchnews to hang (CVE-2005-1911). The updated packages have been patched to correct this problem.
    last seen2020-06-01
    modified2020-06-02
    plugin id18676
    published2005-07-12
    reporterThis script is Copyright (C) 2005-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/18676
    titleMandrake Linux Security Advisory : leafnode (MDKSA-2005:114)
  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_PKG_B5FFAA2AEE504498AF9961BC1B163C00.NASL
    descriptionMatthias Andree reports : A vulnerability was found in the fetchnews program (the NNTP client) that may under some circumstances cause a wait for input that never arrives, fetchnews
    last seen2020-06-01
    modified2020-06-02
    plugin id19091
    published2005-07-13
    reporterThis script is Copyright (C) 2005-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/19091
    titleFreeBSD : leafnode -- denial of service vulnerability (b5ffaa2a-ee50-4498-af99-61bc1b163c00)