The fetchnews NNTP client in leafnode 1.9.3 to 1.9.41 allows remote attackers to cause a denial of service (process hang and termination) via certain malformed Usenet news articles that cause fetchnews to hang while waiting for input.
| Software | From | Fixed in |
|---|---|---|
| leafnode / leafnode | 1.9.26 | 1.9.26.x |
| leafnode / leafnode | 1.9.22 | 1.9.22.x |
| leafnode / leafnode | 1.9.20 | 1.9.20.x |
| leafnode / leafnode | 1.9.30 | 1.9.30.x |
| leafnode / leafnode | 1.9.41 | 1.9.41.x |
| leafnode / leafnode | 1.9.25 | 1.9.25.x |
| leafnode / leafnode | 1.9.19 | 1.9.19.x |
| leafnode / leafnode | 1.9.21 | 1.9.21.x |
| leafnode / leafnode | 1.9.40 | 1.9.40.x |
| leafnode / leafnode | 1.9.23 | 1.9.23.x |
| leafnode / leafnode | 1.9.24 | 1.9.24.x |
| leafnode / leafnode | 1.9.36 | 1.9.36.x |
| leafnode / leafnode | 1.9.37 | 1.9.37.x |
| leafnode / leafnode | 1.9.27 | 1.9.27.x |
| leafnode / leafnode | 1.9.29 | 1.9.29.x |
| leafnode / leafnode | 1.9.38 | 1.9.38.x |
| leafnode / leafnode | 1.9.39 | 1.9.39.x |
| leafnode / leafnode | 1.9.31 | 1.9.31.x |
| leafnode / leafnode | 1.9.35 | 1.9.35.x |