CVE-2012-3534: Buffer Overflow
Published Aug 31, 2012
·Updated
GNU Gatekeeper before 3.1 does not limit the number of connections to the status port, which allows remote attackers to cause a denial of service (connection and thread consumption) via a large number of connections.
Affected Software
28 affected components
openSUSE Leap=42.1
openSUSE openSUSE=13.2
Gnugk Gnu Gatekeeper<=3.1
Gnugk Gnu Gatekeeper=2.0.3
Gnugk Gnu Gatekeeper=2.0.4
Gnugk Gnu Gatekeeper=2.0.5
Gnugk Gnu Gatekeeper=2.0.6
Gnugk Gnu Gatekeeper=2.0.7
Gnugk Gnu Gatekeeper=2.0.8
Gnugk Gnu Gatekeeper=2.0.9
Gnugk Gnu Gatekeeper=2.2.0
Gnugk Gnu Gatekeeper=2.2.1
Gnugk Gnu Gatekeeper=2.2.2
Gnugk Gnu Gatekeeper=2.2.3
Gnugk Gnu Gatekeeper=2.2.4
Gnugk Gnu Gatekeeper=2.2.5
Gnugk Gnu Gatekeeper=2.2.6
Gnugk Gnu Gatekeeper=2.2.7
Gnugk Gnu Gatekeeper=2.2.8
Gnugk Gnu Gatekeeper=2.2.9
Gnugk Gnu Gatekeeper=2.3.0
Gnugk Gnu Gatekeeper=2.3.1
Gnugk Gnu Gatekeeper=2.3.2
Gnugk Gnu Gatekeeper=2.3.3
Gnugk Gnu Gatekeeper=2.3.4
Gnugk Gnu Gatekeeper=2.3.5
Gnugk Gnu Gatekeeper=3.0
Gnugk Gnu Gatekeeper=3.0-beta
Event History
Aug 31, 2012
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-3534?
CVE-2012-3534 is classified as a denial of service vulnerability with moderate severity.
2
How does CVE-2012-3534 affect the GNU Gatekeeper software?
CVE-2012-3534 allows remote attackers to exhaust system resources through an excessive number of connections to the status port.
3
How can I fix CVE-2012-3534?
To address CVE-2012-3534, upgrade to GNU Gatekeeper version 3.1 or later, which includes a limit on connection attempts.
4
What versions of GNU Gatekeeper are affected by CVE-2012-3534?
CVE-2012-3534 affects all versions of GNU Gatekeeper prior to 3.1.
5
Is there a way to mitigate the risks of CVE-2012-3534 before upgrading?
Mitigation strategies for CVE-2012-3534 include implementing firewall rules to limit access to the status port.