CVE-2002-1154

Source
https://nvd.nist.gov/vuln/detail/CVE-2002-1154
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2002-1154.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2002-1154
Published
2002-10-11T04:00:00Z
Modified
2024-11-20T23:40:42Z
Summary
[none]
Details

anlgform.pl in Analog before 5.23 does not restrict access to the PROGRESSFREQ progress update command, which allows remote attackers to cause a denial of service (disk consumption) by using the command to report updates more frequently and fill the web server error log.

References

Affected packages

Debian:11 / analog

Package

Name
analog
Purl
pkg:deb/debian/analog?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:5.23

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / analog

Package

Name
analog
Purl
pkg:deb/debian/analog?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:5.23

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / analog

Package

Name
analog
Purl
pkg:deb/debian/analog?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:5.23

Ecosystem specific

{
    "urgency": "not yet assigned"
}