PT-2007-5539 · Zoidcom · Zoidcom

Published

2007-08-15

·

Updated

2018-10-15

·

CVE-2007-4358

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Zoidcom versions 0.6.7 and earlier
Description The issue allows remote attackers to cause a denial of service, resulting in an application crash. This is achieved by sending a JOIN packet, also known as a connection packet, with specific malicious content. The ninth byte of this packet contains the value 0x69, which triggers a "double-delete" of trace data, leading to the crash.
Recommendations For Zoidcom versions 0.6.7 and earlier, as a temporary workaround, consider restricting or validating the content of JOIN packets to prevent the inclusion of malicious values like 0x69 in the ninth byte. However, at the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-4358

Affected Products

Zoidcom