Bug 821431 (CVE-2007-2195)
Summary: | CVE-2007-2195 amsn: DoS (client crash) via sending invalid data to TCP port 31337 | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Jan Lieskovsky <jlieskov> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | sander |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2021-10-19 21:52:59 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Jan Lieskovsky
2012-05-14 13:08:35 UTC
I was unable to reproduce this issue based on [4]. Upstream bug report for another (CVE-2006-0138) issue mentions this (CVE-2007-2195) issue doesn't exist anymore: [5] http://sourceforge.net/tracker/?func=detail&aid=2921641&group_id=54091&atid=472655 But since I have been having issues to reproduce the CVE-2006-0138 issue too: [6] https://bugzilla.redhat.com/show_bug.cgi?id=821416#c1 someone more familiar with amsn code should have a look at this if it's still an issue or not. Note: Hard to identify relevant upstream SVN commit. Amsn v0.97 Changelog: http://amsn.sourceforge.net/wiki/tiki-index.php?page=ChangeLog mentions: "Only for amsn-remote,fixed possible DoS attack, and make remote not reply to commands when it's not enabled, instead of waiting for authentication and parsing commands, which may lead to parse errors." but I am not sure if this is the fix for CVE-2007-2195 issue. If you upon investigation / testing would realize, this issue is fixed already, feel free to close this report as invalid / notabug. |