Mandrake Linux Security Advisory : leafnode (MDKSA-2003:005)

This script is Copyright (C) 2004-2013 Tenable Network Security, Inc.


Synopsis :

The remote Mandrake Linux host is missing a security update.

Description :

A vulnerability was discovered by Jan Knutar in leafnode that Mark
Brown pointed out could be used in a Denial of Service attack. This
vulnerability causes leafnode to go into an infinite loop with 100%
CPU use when an article that has been crossposed to several groups,
one of which is the prefix of another, is requested by it's
Message-ID.

This vulnerability was introduced in 1.9.20 and fixed upstream in
version 1.9.30. Only Mandrake Linux 9.0 is affected by this, but
version 1.9.19 (which shipped with Mandrake Linux 8.2) is receiving an
update due to critical bugs in it that can corrupt parts of its news
spool under certain circumstances.

See also :

http://marc.info/?l=bugtraq&m=104127108823436&w=2

Solution :

Update the affected leafnode package.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)

Family: Mandriva Local Security Checks

Nessus Plugin ID: 13990 (mandrake_MDKSA-2003-005.nasl)

Bugtraq ID:

CVE ID: CVE-2002-1661

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now