Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 91546 - net-nntp/leafnode: Two Denial of Service Issues
Summary: net-nntp/leafnode: Two Denial of Service Issues
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal
Assignee: Gentoo Security
URL: http://secunia.com/advisories/15252/
Whiteboard: B3 [noglsa] jaervosz
Keywords:
Depends on:
Blocks:
 
Reported: 2005-05-05 02:47 UTC by Adir Abraham
Modified: 2005-05-12 05:51 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Adir Abraham 2005-05-05 02:47:36 UTC
According to Secunia's advisory, there seems to be two DoS issues which are reported in their site.

Solution: update to version 1.11.2. Currently our tree holds versions 1.11.0 and 1.11.1.
(Originally arraived from leafnode's site - http://leafnode.sourceforge.net/leafnode-SA-2005-01.txt)


Reproducible: Always
Steps to Reproduce:
1.
2.
3.
Comment 1 Adir Abraham 2005-05-05 02:59:50 UTC
New stable release is available here: http://prdownloads.sourceforge.net/leafnode/leafnode-1.11.2.rel.tar.bz2?download
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-05-05 07:09:39 UTC
Net-news please advise.
Comment 3 Sven Wegener gentoo-dev 2005-05-05 07:17:07 UTC
leafnode-1.11.2 in CVS and stable on x86.
Comment 4 Michael Hanselmann (hansmi) (RETIRED) gentoo-dev 2005-05-05 07:42:19 UTC
Stable on ppc.
Comment 5 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-05-05 08:03:25 UTC
This one is ready for GLSA vote. I tend to vote NO.
Comment 6 Tavis Ormandy (RETIRED) gentoo-dev 2005-05-10 00:57:49 UTC
I would agree, NO to this very minor issue.
Comment 7 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-05-10 07:51:29 UTC
1
Comment 8 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-05-10 07:51:29 UTC
1½ NO vote so far.
Comment 9 Thierry Carrez (RETIRED) gentoo-dev 2005-05-12 05:51:35 UTC
DoS on client... Voting no and closing.