The leafnode server in leafnode 1.9.20 to 1.9.29 allows remote attackers to cause a denial of service (infinite loop) when leafnode requests a cross-posted article to one group whose name is a prefix of another group.
| Software | From | Fixed in |
|---|---|---|
| leafnode / leafnode | 1.9.26 | 1.9.26.x |
| leafnode / leafnode | 1.9.22 | 1.9.22.x |
| leafnode / leafnode | 1.9.20 | 1.9.20.x |
| leafnode / leafnode | 1.9.25 | 1.9.25.x |
| leafnode / leafnode | 1.9.19 | 1.9.19.x |
| leafnode / leafnode | 1.9.21 | 1.9.21.x |
| leafnode / leafnode | 1.9.27 | 1.9.27.x |
| leafnode / leafnode | 1.9.24 | 1.9.24.x |
| leafnode / leafnode | 1.9.23 | 1.9.23.x |
| leafnode / leafnode | 1.9.29 | 1.9.29.x |