PT-2008-4390 · Linuxdcpp · Linuxdcpp

Published

2008-07-01

·

Updated

2017-08-08

·

CVE-2008-2954

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions linuxdcpp versions prior to 1.0.0 is not specified, however, the version before 0.707 is affected, so: linuxdcpp versions prior to 0.707
Description The issue allows remote attackers to cause a denial of service, resulting in a crash, by sending an empty private message. This triggers an out-of-bounds read in the client/NmdcHub.cpp file.
Recommendations For versions prior to 0.707, update to version 0.707 or later to resolve the issue.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-2954

Affected Products

Linuxdcpp