MICO Object Key Remote Denial of Service Vulnerability
BID:18869
CVE-2006-3492 |Info
MICO Object Key Remote Denial of Service Vulnerability
| Bugtraq ID: | 18869 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2006-3492 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 06 2006 12:00AM |
| Updated: | Feb 11 2016 07:43AM |
| Credit: | tuergeist <[email protected]> discovered this issue. |
| Vulnerable: |
MICO Project Team MICO 2.3.12 RC3 MICO Project Team MICO 2.3.12 |
| Not Vulnerable: | |
Discussion
MICO Object Key Remote Denial of Service Vulnerability
MICO is susceptible to a remote denial-of-service vulnerability. This issue is due to a failure of the application to properly handle unexpected input.
This issue allows remote attackers to crash affected applications, denying further service to legitimate users.
MICO versions 2.3.12RC3 and 2.3.12 are vulnerable to this issue; other versions may also be affected.
MICO is susceptible to a remote denial-of-service vulnerability. This issue is due to a failure of the application to properly handle unexpected input.
This issue allows remote attackers to crash affected applications, denying further service to legitimate users.
MICO versions 2.3.12RC3 and 2.3.12 are vulnerable to this issue; other versions may also be affected.
Exploit / POC
MICO Object Key Remote Denial of Service Vulnerability
The following code examples can be used to demonstrate this issue.
Once the server application located in the 'mico_bug.tgz' file has been started, the following command will reportedly trigger this issue:
java JPing -p corbaloc:: 192.168.1.10:8010//200/1151845678/0/_5
The following code examples can be used to demonstrate this issue.
Once the server application located in the 'mico_bug.tgz' file has been started, the following command will reportedly trigger this issue:
java JPing -p corbaloc:: 192.168.1.10:8010//200/1151845678/0/_5
Solution / Fix
MICO Object Key Remote Denial of Service Vulnerability
Solution:
Vendor released a security patch to address this issue. Please see references for details.
Solution:
Vendor released a security patch to address this issue. Please see references for details.
References
MICO Object Key Remote Denial of Service Vulnerability
References:
References:
- MICO Home Page (MICO)
- MICO Homepage Security Update (Mico )
- Mico crashes when contected with wrong IOR / DoS (tuergeist)
- Mico crashes when contected with wrong IOR / DoS (tuergeist
)