Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2004-2534

Overview

Vulnerability Score 7.8 7.8
CVE Id CVE-2004-2534
Last Modified 05 Sep 2008 12:00:00
Published 31 Dec 2004 12:00:00
Confidentiality Impact NONE NONE
Integrity Impact NONE NONE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2004-2534

Summary

Fastream NETFile Server 7.1.2 does not properly handle keep-alive connection timeouts and does not close the connection after a HEAD request, which allows remote attackers to perform a denial of service (connection consumption) by sending a large number HTTP HEAD requests.

Vulnerable Systems

Application

  • Fastream Netfile Server 6.5.1.980

  • Fastream Netfile Server 6.5.1.981

  • Fastream Netfile Server 6.7.2.1085

  • Fastream Netfile Server 6.7.3

  • Fastream Netfile Server 6.7.5

  • Fastream Netfile Server 7.1

  • Fastream Netfile Server 7.1.2


References

SECUNIA - 13268

XF - fastream-head-request-dos(18192)

BID - 11687

OSVDB - 12101

MISC - http://users.pandora.be/bratax/advisories/b003.html

SECTRACK - 1012267


Last Updated: 27 May 2016 10:39:30