[原文]The License Manager (mathlm) for Mathematica 4.0 and 4.1 allows remote attackers to cause a denial of service (resource exhaustion) by connecting to port 16286 and not disconnecting, which prevents users from making license requests.


        Mathematica是一个由Wolfram Research发布和维护的数学计算软件包。

This vulnerability was announced to Bugtraq by Pinwheel <> on July 30, 2001.

- 受影响的程序版本

Wolfram Research Mathematica 4.1
Wolfram Research Mathematica 4.0

Mathematica is a math calculation software package distributed and maintained by Wolfram Research.

The Mathematica License Manager does not correctly handle connection requests. Upon receiving a request from a client, the server does not fork established connections to a seperate port for service. Additionally, a client placing a request the server can not interpret is not disconnected.

This makes it possible for a remote user to deny service to legitimate users of the service.

