CVE-2002-2244

Severity CVSS v4.0:
Pending analysis
Type:
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
31/12/2002
Last modified:
29/07/2017

Description

Akfingerd 0.5 and earlier versions allow local users to cause a denial of service (crash) via a .plan with a symlink to /dev/urandom or other device, then disconnecting while data is being transferred, which causes a SIGPIPE error that Akfingerd cannot handle.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:akfingerd:akfingerd:0.5:*:*:*:*:*:*:*