Zebedee Remote Denial Of Service Vulnerability
BID:14796
Info
Zebedee Remote Denial Of Service Vulnerability
| Bugtraq ID: | 14796 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 09 2005 12:00AM |
| Updated: | Sep 09 2005 12:00AM |
| Credit: | "Shiraishi.M" <[email protected]> disclosed this vulnerability. |
| Vulnerable: |
Zebedee Zebedee 2.4.1 |
| Not Vulnerable: |
Zebedee Zebedee 2.4.1 A |
Discussion
Zebedee Remote Denial Of Service Vulnerability
A remote denial of service vulnerability affects Zebedee. This issue is due to a failure of the application to properly handle exceptional network requests.
Specifically, Zebedee is unable to handle requests for connections that contain a zero for the requested destination port.
A remote attacker may leverage this issue to crash the affected application, denying service to legitimate users.
Zebedee version 2.4.1 is reported vulnerable to this issue; other versions may also be affected.
A remote denial of service vulnerability affects Zebedee. This issue is due to a failure of the application to properly handle exceptional network requests.
Specifically, Zebedee is unable to handle requests for connections that contain a zero for the requested destination port.
A remote attacker may leverage this issue to crash the affected application, denying service to legitimate users.
Zebedee version 2.4.1 is reported vulnerable to this issue; other versions may also be affected.
Exploit / POC
Zebedee Remote Denial Of Service Vulnerability
An exploit is not required.
An application designed to create data sufficient to trigger this issue is available:
An exploit is not required.
An application designed to create data sufficient to trigger this issue is available:
Solution / Fix
Zebedee Remote Denial Of Service Vulnerability
Solution:
Gentoo has released fixes to address this issue. Gentoo fixes may be applied by running the following commands as the superuser:
emerge --sync
emerge --ask --oneshot --verbose net-misc/zebedee
The vendor has released version 2.4.1A to address this issue:
Zebedee Zebedee 2.4.1
Solution:
Gentoo has released fixes to address this issue. Gentoo fixes may be applied by running the following commands as the superuser:
emerge --sync
emerge --ask --oneshot --verbose net-misc/zebedee
The vendor has released version 2.4.1A to address this issue:
Zebedee Zebedee 2.4.1
-
Zebedee zebedee-2.4.1A.tar.gz
http://prdownloads.sourceforge.net/zebedee/zebedee-2.4.1A.tar.gz?downl oad
References
Zebedee Remote Denial Of Service Vulnerability
References:
References:
- Zebedee Home Page (Zebedee)
- Zebedee DoS Vulnerability ("Shiraishi.M"
)