Vulnerability Description
Memory leak in the login_user function in saslserv/main.c in saslserv/main.so in Atheme 7.2.7 allows a remote unauthenticated attacker to consume memory and cause a denial of service. This is fixed in 7.2.8.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Atheme | Atheme | 7.2.7 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/96552
- https://github.com/atheme/atheme/pull/539Issue TrackingPatchThird Party Advisory
- https://github.com/atheme/atheme/releases/tag/v7.2.8PatchRelease NotesVendor Advisory
- http://www.securityfocus.com/bid/96552
- https://github.com/atheme/atheme/pull/539Issue TrackingPatchThird Party Advisory
- https://github.com/atheme/atheme/releases/tag/v7.2.8PatchRelease NotesVendor Advisory
FAQ
What is CVE-2017-6384?
CVE-2017-6384 is a vulnerability with a CVSS score of 7.5 (HIGH). Memory leak in the login_user function in saslserv/main.c in saslserv/main.so in Atheme 7.2.7 allows a remote unauthenticated attacker to consume memory and cause a denial of service. This is fixed in...
How severe is CVE-2017-6384?
CVE-2017-6384 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-6384?
Check the references section above for vendor advisories and patch information. Affected products include: Atheme Atheme.