GDM 2.4.4.x before 2.4.4.4, and 2.4.1.x before 2.4.1.7,...
Low severity
Unreviewed
Published
Apr 29, 2022
to the GitHub Advisory Database
•
Updated Jan 30, 2023
Description
Published by the National Vulnerability Database
Nov 17, 2003
Published to the GitHub Advisory Database
Apr 29, 2022
Last updated
Jan 30, 2023
GDM 2.4.4.x before 2.4.4.4, and 2.4.1.x before 2.4.1.7, does not limit the number or duration of commands and uses a blocking socket connection, which allows attackers to cause a denial of service (resource exhaustion) by sending commands and not reading the results.
References