The HTTPSTK service in the novell-nrm package before 2.0.2-297.305.302.3 in Novell Open Enterprise Server 2 (OES 2) Linux, and OES 11 Linux Gold and SP1, does not make the intended SSL_free and SSL_shutdown calls for the close of a TCP connection, which allows remote attackers to cause a denial of service (service crash) by establishing many TCP connections to port 8009.
Advisories
Source ID Title
EUVD EUVD EUVD-2013-3640 The HTTPSTK service in the novell-nrm package before 2.0.2-297.305.302.3 in Novell Open Enterprise Server 2 (OES 2) Linux, and OES 11 Linux Gold and SP1, does not make the intended SSL_free and SSL_shutdown calls for the close of a TCP connection, which allows remote attackers to cause a denial of service (service crash) by establishing many TCP connections to port 8009.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T16:14:56.653Z

Reserved: 2013-05-30T00:00:00

Link: CVE-2013-3707

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2013-12-01T17:55:05.147

Modified: 2025-04-11T00:51:21.963

Link: CVE-2013-3707

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.