PT-2007-2733 · Silc · Silc Server
Published
2007-03-07
·
Updated
2017-07-29
·
CVE-2007-1327
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
silc-server version 1.0.2
Description
The issue allows remote attackers to cause a denial of service, resulting in a daemon crash due to a NULL dereference. This occurs when a request is made without a cipher algorithm and with an invalid HMAC algorithm, specifically targeting the SILC SERVER CMD FUNC function in the silcd/command.c application.
Recommendations
For silc-server version 1.0.2, as a temporary workaround, consider disabling the SILC SERVER CMD FUNC function until a patch is available. Restrict access to the silcd/command.c application to minimize the risk of exploitation. Avoid processing requests without a cipher algorithm and with an invalid HMAC algorithm in the affected function.
Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Silc Server