6tunnel 0.08 and earlier does not properly close sockets that were initiated by a client, which allows remote attackers to cause a denial of service (resource exhaustion) by repeatedly connecting to and disconnecting from the server.
References
Link | Resource |
---|---|
ftp://213.146.38.146/pub/wojtekka/6tunnel-0.09.tar.gz | Broken Link |
http://marc.info/?l=bugtraq&m=100386451702966&w=2 | Exploit Mailing List |
http://www.securityfocus.com/bid/3467 | Broken Link Third Party Advisory VDB Entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/7337 | Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 2001-12-06 05:00
Updated : 2024-02-09 02:52
NVD link : CVE-2001-0830
Mitre link : CVE-2001-0830
CVE.ORG link : CVE-2001-0830
JSON object : View
Products Affected
6tunnel_project
- 6tunnel
CWE
CWE-772
Missing Release of Resource after Effective Lifetime