Title: Akfingerd Local Denial Of Service Attack
Severity: LOW
Description:
akfingerd is a small fingerd replacement. It is available for Unix and Linux operating systems.
A bug has been discovered in akfingerd that makes it possible for a local user to cause a denial of service. It is possible to trigger this issue by creating a situation which allows the attacker to terminate the client while the daemon is still writing data to the socket. This will cause a SIGPIPE signal to be sent to the server. Due to insufficient handling of the SIGPIPE signal, the akfingerd service will crash.
It should be noted that this vulnerability was discovered in akfingerd 0.5. It is not known whether earlier versions are also affected.
Affected Products:
- akfingerd akfingerd 0.5.0
References:
- www.synflood.at: Akfingerd Product Page
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.