DConnect Daemon DC Chat Denial of Service Vulnerability
BID:19370
CVE-2006-4126 |Info
DConnect Daemon DC Chat Denial of Service Vulnerability
| Bugtraq ID: | 19370 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 06 2006 12:00AM |
| Updated: | Aug 07 2006 12:51AM |
| Credit: | Luigi Auriemma is credited with the discovery of this issue. |
| Vulnerable: |
DConnect DConnect Daemon 0.7 DConnect DConnect Daemon 0.0.3 DConnect DConnect Daemon 0.0.2 DConnect DConnect Daemon CVS 30 Jul 2006 |
| Not Vulnerable: |
DConnect DConnect Daemon CVS 31 Jul 2006 |
Discussion
DConnect Daemon DC Chat Denial of Service Vulnerability
DConnect Daemon is prone to a denial-of-service vulnerability.
This issue occurs because the application fails to handle null-pointer exceptions properly.
An attacker can exploit this issue to crash the server, causing a denial-of-service.
Version 0.7.0, CVS July 30th 2006 and prior versions are vulnerable to this issue.
DConnect Daemon is prone to a denial-of-service vulnerability.
This issue occurs because the application fails to handle null-pointer exceptions properly.
An attacker can exploit this issue to crash the server, causing a denial-of-service.
Version 0.7.0, CVS July 30th 2006 and prior versions are vulnerable to this issue.
Exploit / POC
DConnect Daemon DC Chat Denial of Service Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
DConnect Daemon DC Chat Denial of Service Vulnerability
Solution:
The vendor has released an update to address this issue. Please contact the vendor on how to obtain this update.
Solution:
The vendor has released an update to address this issue. Please contact the vendor on how to obtain this update.
References
DConnect Daemon DC Chat Denial of Service Vulnerability
References:
References:
- DConnect Daemon (Luigi Auriemma)
- DConnect Daemon Home Page (DConnect)