Hiki Diff Denial Of Service Vulnerability
BID:18785
CVE-2006-3379 |Info
Hiki Diff Denial Of Service Vulnerability
| Bugtraq ID: | 18785 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2006-3379 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 03 2006 12:00AM |
| Updated: | Jul 27 2006 08:57PM |
| Credit: | This issue was reported by the vendor. |
| Vulnerable: |
Hiki Hiki 0.8.5 Hiki Hiki 0.8.4 Hiki Hiki 0.8.3 Hiki Hiki 0.8.2 Hiki Hiki 0.8.1 Hiki Hiki 0.8 Hiki Hiki 0.6.5 Hiki Hiki 0.6.4 Hiki Hiki 0.6.3 Hiki Hiki 0.6.2 Hiki Hiki 0.6.1 Hiki Hiki 0.6 FreeStyle Wiki Wiki 3.5.9 FreeStyle Wiki Wiki 3.5.8 FreeStyle Wiki Wiki 3.5.7 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
Hiki Hiki 0.8.6 FreeStyle Wiki Wiki 3.6.2 |
Discussion
Hiki Diff Denial Of Service Vulnerability
Hiki is prone to a denial-of-service vulnerability because of an error when processing a comparison between two pages.
An attacker can exploit this vulnerability to cause the application to stop responding due to excessive use of system resources, denying service to legitimate users.
Hiki is prone to a denial-of-service vulnerability because of an error when processing a comparison between two pages.
An attacker can exploit this vulnerability to cause the application to stop responding due to excessive use of system resources, denying service to legitimate users.
Exploit / POC
Hiki Diff Denial Of Service Vulnerability
Attackers can exploit this vulnerability via a web browser.
Attackers can exploit this vulnerability via a web browser.
Solution / Fix
Hiki Diff Denial Of Service Vulnerability
Solution:
The vendor has released version 0.8.6 to address this issue.
See the references for vendor advisories.
Hiki Hiki 0.6.5
Solution:
The vendor has released version 0.8.6 to address this issue.
See the references for vendor advisories.
Hiki Hiki 0.6.5
-
Debian hiki_0.6.5-2_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hiki/hiki_0.6.5-2_all.d eb
References
Hiki Diff Denial Of Service Vulnerability
References:
References:
- Freestyle Wiki Homepage (Freestyle Wiki)
- Hiki Homepage (Hiki)
- Hiki Security Advisory (Hiki )