LeadMind Pop Messenger Illegal Character Remote Denial Of Service Vulnerability
BID:11230
Info
LeadMind Pop Messenger Illegal Character Remote Denial Of Service Vulnerability
| Bugtraq ID: | 11230 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 21 2004 12:00AM |
| Updated: | Sep 21 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Luigi Auriemma <[email protected]>. |
| Vulnerable: |
LeadMind PopMessenger 1.60 |
| Not Vulnerable: | |
Discussion
LeadMind Pop Messenger Illegal Character Remote Denial Of Service Vulnerability
LeadMind Pop Messenger is reported prone to a remote denial of service vulnerability. The issue exists because the messenger application fails to gracefully handle certain characters that are received.
A remote attacker may exploit this vulnerability to crash the LeadMind Pop Messenger client. Additionally, it is reported that an attacker may broadcast a malicious message to all clients on the connected local network segment and deny service to all of the clients at once.
LeadMind Pop Messenger is reported prone to a remote denial of service vulnerability. The issue exists because the messenger application fails to gracefully handle certain characters that are received.
A remote attacker may exploit this vulnerability to crash the LeadMind Pop Messenger client. Additionally, it is reported that an attacker may broadcast a malicious message to all clients on the connected local network segment and deny service to all of the clients at once.
Exploit / POC
LeadMind Pop Messenger Illegal Character Remote Denial Of Service Vulnerability
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
LeadMind Pop Messenger Illegal Character Remote Denial Of Service Vulnerability
Solution:
It is reported that the vendor has addressed this issue in versions of Pop Messenger that were released after the 20th of September 2004. This is not confirmed.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
LeadMind PopMessenger 1.60
Solution:
It is reported that the vendor has addressed this issue in versions of Pop Messenger that were released after the 20th of September 2004. This is not confirmed.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
LeadMind PopMessenger 1.60
-
LeadMind pmesseng.exe
http://www.leadmind.com/pmesseng.exe
References
LeadMind Pop Messenger Illegal Character Remote Denial Of Service Vulnerability
References:
References:
- Pop Messenger Homepage (LeadMind)
- Broadcast crash in Popmessenger 1.60 (before 20 Sep 2004) (Luigi Auriemma
)