#VU50039 Resource exhaustion in ServerProtect for Linux - CVE-2021-25224
Published: January 26, 2021 / Updated: January 27, 2021
ServerProtect for Linux
Trend Micro
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
Three vulnerabilities exists due to application does not properly control consumption of internal resources within the splx_manual_scan executable. A local user can trigger resource exhaustion and perform a denial of service (DoS) attack.
Remediation
Install updates from vendor's website.
https://files.trendmicro.com/products/serverprotect/splx_30_lx_en_criticalpatch1649.tar.gz