Exceed Denial of Service Vulnerability
BID:158
Info
Exceed Denial of Service Vulnerability
| Bugtraq ID: | 158 |
| Class: | Unknown |
| CVE: |
CVE-1999-1196 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 27 1999 12:00AM |
| Updated: | Jul 11 2009 12:16AM |
| Credit: | This vulnerability was reported by Chris J. LaFournaise <[email protected]> to the Bugtraq mailing list. |
| Vulnerable: |
Hummingbird Exceed 5.0 |
| Not Vulnerable: |
Hummingbird Exceed 6.1 Hummingbird Exceed 6.0.2 Hummingbird Exceed 6.0.1 |
Discussion
Exceed Denial of Service Vulnerability
The Exceed X server is an X Windows server for Windows 95/98 and WindowsNT. The server listens for connections on port 6000. Connecting to this port from any IP address and entering random data hangs the server.
The newer versions of the server are not vulnerable to this attack but they hang anywhere from a couple of seconds to a couple of minutes when a connections is made to the port from any IP address. A small script that continually connects to the server can in practice freeze the server.
The Exceed X server is an X Windows server for Windows 95/98 and WindowsNT. The server listens for connections on port 6000. Connecting to this port from any IP address and entering random data hangs the server.
The newer versions of the server are not vulnerable to this attack but they hang anywhere from a couple of seconds to a couple of minutes when a connections is made to the port from any IP address. A small script that continually connects to the server can in practice freeze the server.
Exploit / POC
Exceed Denial of Service Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Exceed Denial of Service Vulnerability
Solution:
Upgrade to a non-vulnerable version of Exceed.
Solution:
Upgrade to a non-vulnerable version of Exceed.
References
Exceed Denial of Service Vulnerability
References:
References: