Neslo Desktop Rover Malformed Packet Remote Denial Of Service Vulnerability

BID:13281

Info

Neslo Desktop Rover Malformed Packet Remote Denial Of Service Vulnerability

Bugtraq ID: 13281
Class: Failure to Handle Exceptional Conditions
CVE:
Remote: Yes
Local: No
Published: Apr 20 2005 12:00AM
Updated: Apr 20 2005 12:00AM
Credit: Discovery of this issue is credited to Adam Baldwin <[email protected]>.
Vulnerable: Neslo Desktop Rover 3.0
Not Vulnerable:

Discussion

Neslo Desktop Rover Malformed Packet Remote Denial Of Service Vulnerability

Neslo Desktop Rover is prone to a remote denial of service. Reports indicate that the software will crash when a malformed packet is processed on TCP port 61427.

A remote attacker may exploit this condition crash the software and effectively deny service for legitimate users.

Exploit / POC

Neslo Desktop Rover Malformed Packet Remote Denial Of Service Vulnerability

The following packet trace is available:

20:23:48.778009 192.168.28.133.32771 > 192.168.28.129.61427: P [tcp sum ok]
1:13(12) ack 1 win 5840 (DF) (ttl 64, id 24051, len 64)

4500 0040 5df3 4000 4006 226e c0a8 1c85
c0a8 1c81 8003 eff3 90a8 d150 7cda 8afa
8018 16d0 daab 0000 0101 080a 0000 8cbe
0000 0000 6352 0100 0000 0000 0000 0000

Solution / Fix

Neslo Desktop Rover Malformed Packet Remote Denial Of Service Vulnerability

Solution:
The discoverer of this issue reports that the vendor is intending to address this issue in version 3.1 of the software. This is not confirmed. Customers are advised to contact the vendor for further information.

Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

References

Neslo Desktop Rover Malformed Packet Remote Denial Of Service Vulnerability

References:
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report