Apache James Spooler Memory Leak Denial Of Service Vulnerability
BID:15765
Info
Apache James Spooler Memory Leak Denial Of Service Vulnerability
| Bugtraq ID: | 15765 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 07 2005 12:00AM |
| Updated: | Dec 07 2005 12:00AM |
| Credit: | This issue was disclosed by the vendor. |
| Vulnerable: |
Apache James 2.2 |
| Not Vulnerable: | |
Discussion
Apache James Spooler Memory Leak Denial Of Service Vulnerability
James is prone to a memory leak denial of service vulnerability.
This issue occurs during an error condition in the spooler.
An attacker can exploit this issue by creating multiple error conditions and eventually consume system resources.
Successful exploitation will ultimately crash the application denying service to legitimate users.
James is prone to a memory leak denial of service vulnerability.
This issue occurs during an error condition in the spooler.
An attacker can exploit this issue by creating multiple error conditions and eventually consume system resources.
Successful exploitation will ultimately crash the application denying service to legitimate users.
Exploit / POC
Apache James Spooler Memory Leak Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Apache James Spooler Memory Leak Denial Of Service Vulnerability
Solution:
The vendor has addressed this issue in the CVS. Users are advised to contact the vendor for further information.
Solution:
The vendor has addressed this issue in the CVS. Users are advised to contact the vendor for further information.
References
Apache James Spooler Memory Leak Denial Of Service Vulnerability
References:
References:
- James Changelog (Apache Software Foundation)
- James Homepage (Apache Software Foundation)
- Spooler.accept(...) can leave locked messages and leak memory (Apache Software Foundation)