The leafnode server in leafnode 1.9.20 to 1.9.29 allows remote attackers to cause a denial of service (infinite loop) when leafnode requests a cross-posted article to one group whose name is a prefix of another group.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Leafnode | Leafnode | 1.9.19 (including) | 1.9.19 (including) |
Leafnode | Leafnode | 1.9.20 (including) | 1.9.20 (including) |
Leafnode | Leafnode | 1.9.21 (including) | 1.9.21 (including) |
Leafnode | Leafnode | 1.9.22 (including) | 1.9.22 (including) |
Leafnode | Leafnode | 1.9.23 (including) | 1.9.23 (including) |
Leafnode | Leafnode | 1.9.24 (including) | 1.9.24 (including) |
Leafnode | Leafnode | 1.9.25 (including) | 1.9.25 (including) |
Leafnode | Leafnode | 1.9.26 (including) | 1.9.26 (including) |
Leafnode | Leafnode | 1.9.27 (including) | 1.9.27 (including) |
Leafnode | Leafnode | 1.9.29 (including) | 1.9.29 (including) |