Gadu-Gadu Remote User Addition unauthorized Access Vulnerability
BID:26722
Info
Gadu-Gadu Remote User Addition unauthorized Access Vulnerability
| Bugtraq ID: | 26722 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 05 2007 12:00AM |
| Updated: | Dec 06 2007 05:02AM |
| Credit: | Michal Bucko is credited with the discovery of this issue. |
| Vulnerable: |
Gadu-Gadu Gadu-Gadu 7.7 |
| Not Vulnerable: | |
Discussion
Gadu-Gadu Remote User Addition unauthorized Access Vulnerability
Gadu-Gadu is prone to a vulnerability that allows unauthorized users to add additional users. This issue occurs because of improper protocol handling by its default handler, 'gg'.
Remote attackers can exploit this issue to remotely add users to the application. Attackers may be able to trigger denial-of-service conditions.
Gadu-Gadu 7.7 is vulnerable; other versions may also be affected.
Gadu-Gadu is prone to a vulnerability that allows unauthorized users to add additional users. This issue occurs because of improper protocol handling by its default handler, 'gg'.
Remote attackers can exploit this issue to remotely add users to the application. Attackers may be able to trigger denial-of-service conditions.
Gadu-Gadu 7.7 is vulnerable; other versions may also be affected.
Exploit / POC
Gadu-Gadu Remote User Addition unauthorized Access Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim into following a specially crafted URI.
An attacker can exploit this issue by enticing an unsuspecting victim into following a specially crafted URI.
Solution / Fix
Gadu-Gadu Remote User Addition unauthorized Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Gadu-Gadu Remote User Addition unauthorized Access Vulnerability
References:
References:
- Vendor Homepage (Gadu-Gadu)
- [ELEYTT] Public Advisory 05-12-2007 ('Michal Bucko'
)