CVE-2017-6384: High severity Atheme Atheme vulnerability
Memory leak in the loginuser function in saslserv/main.c in saslserv/main.so in Atheme 7.2.7 allows a remote unauthenticated attacker to consume memory and cause a denial of service. This is fixed in 7.2.8.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Atheme saslservto a version that resolves this vulnerability.Fixed in 7.2.8
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6384?
CVE-2017-6384 has a severity rating of medium due to its potential to cause denial of service through memory consumption.
How do I fix CVE-2017-6384?
To fix CVE-2017-6384, upgrade Atheme to version 7.2.8 or later.
What causes CVE-2017-6384?
CVE-2017-6384 is caused by a memory leak in the login_user function in Atheme version 7.2.7.
Can CVE-2017-6384 be exploited remotely?
Yes, CVE-2017-6384 can be exploited by remote unauthenticated attackers.
Is CVE-2017-6384 present in earlier versions of Atheme?
CVE-2017-6384 is found in Atheme version 7.2.7 and is not present in versions after 7.2.8.