Mandrake Linux Security Advisory : leafnode (MDKSA-2003:005)
Medium Nessus Plugin ID 13990
SynopsisThe remote Mandrake Linux host is missing a security update.
DescriptionA vulnerability was discovered by Jan Knutar in leafnode that Mark Brown pointed out could be used in a Denial of Service attack. This vulnerability causes leafnode to go into an infinite loop with 100% CPU use when an article that has been crossposed to several groups, one of which is the prefix of another, is requested by it's Message-ID.
This vulnerability was introduced in 1.9.20 and fixed upstream in version 1.9.30. Only Mandrake Linux 9.0 is affected by this, but version 1.9.19 (which shipped with Mandrake Linux 8.2) is receiving an update due to critical bugs in it that can corrupt parts of its news spool under certain circumstances.
SolutionUpdate the affected leafnode package.