Intruder Client Remote Denial of Service Vulnerability
BID:14347
Info
Intruder Client Remote Denial of Service Vulnerability
| Bugtraq ID: | 14347 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 21 2005 12:00AM |
| Updated: | Jul 21 2005 12:00AM |
| Credit: | [email protected] is credited with the discovery of this vulnerability. |
| Vulnerable: |
Intruder Intruder 1.0 |
| Not Vulnerable: | |
Discussion
Intruder Client Remote Denial of Service Vulnerability
Intruder is prone to a remote denial of service vulnerability. This issue is due to a failure in the application to handle exceptional conditions.
The application fails to deal with data received in a proper manner. An attacker can exploit this vulnerability by sending malicious data to the affected application and crash it, denying service to legitimate users. Reports indicate an attacker can also rename arbitrary files on the affected machine; other attacks may also be possible.
Intruder is prone to a remote denial of service vulnerability. This issue is due to a failure in the application to handle exceptional conditions.
The application fails to deal with data received in a proper manner. An attacker can exploit this vulnerability by sending malicious data to the affected application and crash it, denying service to legitimate users. Reports indicate an attacker can also rename arbitrary files on the affected machine; other attacks may also be possible.
Exploit / POC
Intruder Client Remote Denial of Service Vulnerability
The following exploit has been provided; users are advised to only examine the exploit and not execute it as it makes some modifications to the local system.
The following exploit has been provided; users are advised to only examine the exploit and not execute it as it makes some modifications to the local system.
Solution / Fix
Intruder Client Remote Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Intruder Client Remote Denial of Service Vulnerability
References:
References:
- Intruder Command Execution DOS Exploit (milw0rm)