PT-2007-2071 · Apple · Ichat+3

Published

2007-01-31

·

Updated

2008-09-05

·

CVE-2007-0613

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions mDNSResponder in Apple Mac OS X version 10.4.8 iChat version 3.1.6 InstantMessage framework version 428 in Apple Mac OS X version 10.4.8
Description The issue is related to the Bonjour functionality in the affected software, which does not check for duplicate entries when adding newly discovered available contacts. This allows remote attackers to cause a denial of service, disrupting communication, by sending a flood of duplicate presence. tcp mDNS queries.
Recommendations For mDNSResponder in Apple Mac OS X version 10.4.8, consider restricting access to the Bonjour functionality to minimize the risk of exploitation. For iChat version 3.1.6, avoid using the InstantMessage framework until the issue is resolved. For InstantMessage framework version 428 in Apple Mac OS X version 10.4.8, as a temporary workaround, consider disabling the framework until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-0613

Affected Products

Instantmessage Framework
Macos X
Ichat
Mdnsresponder