PT-2006-4973 · Arcsoft · Arcsoft Mms Composer
Collin R. Mulliner
+1
·
Published
2006-08-14
·
Updated
2018-10-17
·
CVE-2006-4132
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
ArcSoft MMS Composer versions 1.5.5.6 and earlier
ArcSoft MMS Composer versions 2.0.0.13 and earlier
Description
The issue allows remote attackers to cause a denial of service, resulting in resource exhaustion and application crash. This can be achieved via WAPPush messages sent to UDP port 2948.
Recommendations
For versions 1.5.5.6 and earlier, restrict access to UDP port 2948 to minimize the risk of exploitation.
For versions 2.0.0.13 and earlier, consider disabling the WAPPush message handling functionality until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Arcsoft Mms Composer