PT-2007-2733 · Silc · Silc Server

Published

2007-03-07

·

Updated

2017-07-29

·

CVE-2007-1327

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions silc-server version 1.0.2
Description The issue allows remote attackers to cause a denial of service, resulting in a daemon crash due to a NULL dereference. This occurs when a request is made without a cipher algorithm and with an invalid HMAC algorithm, specifically targeting the SILC SERVER CMD FUNC function in the silcd/command.c application.
Recommendations For silc-server version 1.0.2, as a temporary workaround, consider disabling the SILC SERVER CMD FUNC function until a patch is available. Restrict access to the silcd/command.c application to minimize the risk of exploitation. Avoid processing requests without a cipher algorithm and with an invalid HMAC algorithm in the affected function.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-1327

Affected Products

Silc Server