VulnerabilityModified
CVE-2002-2124
The recvn and sendn functions in nylon 0.2 do not check when the recv function call returns 0, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) by closing the connection while recv is executing.
MEDIUM 5.0EPSS 1.59%
Does this matter?
Lower severity and a low EPSS score (1.59%). Track it; it rarely justifies an emergency change on its own.
Description
The recvn and sendn functions in nylon 0.2 do not check when the recv function call returns 0, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) by closing the connection while recv is executing.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 1.59% probability · 74th percentile
- CISA KEV
- Not listed
- Affected
- nylon/nylon
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/7281Vendor Advisory
- http://www.security-express.com/archives/bugtraq/2002-10/0146.html
- http://www.securityfocus.com/bid/5938Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10334
- http://secunia.com/advisories/7281Vendor Advisory
- http://www.security-express.com/archives/bugtraq/2002-10/0146.html
- http://www.securityfocus.com/bid/5938Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10334
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.