PT-2007-5539 · Zoidcom · Zoidcom
Published
2007-08-15
·
Updated
2018-10-15
·
CVE-2007-4358
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Zoidcom versions 0.6.7 and earlier
Description
The issue allows remote attackers to cause a denial of service, resulting in an application crash. This is achieved by sending a JOIN packet, also known as a connection packet, with specific malicious content. The ninth byte of this packet contains the value 0x69, which triggers a "double-delete" of trace data, leading to the crash.
Recommendations
For Zoidcom versions 0.6.7 and earlier, as a temporary workaround, consider restricting or validating the content of JOIN packets to prevent the inclusion of malicious values like 0x69 in the ninth byte. However, at the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zoidcom