SpyNet Chat Server Multiple Connection Denial Of Service Vulnerability
BID:2701
Info
SpyNet Chat Server Multiple Connection Denial Of Service Vulnerability
| Bugtraq ID: | 2701 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2001-0581 |
| Remote: | Yes |
| Local: | No |
| Published: | May 07 2001 12:00AM |
| Updated: | Jul 11 2009 06:06AM |
| Credit: | This vulnerability was announced to Bugtraq on May 7, 2001 by nemesystm <[email protected]>. |
| Vulnerable: |
Spytech Spynet Chat 6.5 |
| Not Vulnerable: | |
Discussion
SpyNet Chat Server Multiple Connection Denial Of Service Vulnerability
Spynet Chat Server is a freely available client-server chat package by Spytech Software. Spynet Chat offers IRC style chat to users of the software package.
A problem in the package could allow remote users to crash the chat server. Upon receiving 100 connection requests from a host within a short period of time, and then receiving a message from same host via the chat client, the chat server exits abnormally. A manual restart is required to resume service.
This problem makes it possible for remote users to crash a Spynet Chat Server, denying service to legimate users.
Spynet Chat Server is a freely available client-server chat package by Spytech Software. Spynet Chat offers IRC style chat to users of the software package.
A problem in the package could allow remote users to crash the chat server. Upon receiving 100 connection requests from a host within a short period of time, and then receiving a message from same host via the chat client, the chat server exits abnormally. A manual restart is required to resume service.
This problem makes it possible for remote users to crash a Spynet Chat Server, denying service to legimate users.
Exploit / POC
SpyNet Chat Server Multiple Connection Denial Of Service Vulnerability
x
x
Solution / Fix
SpyNet Chat Server Multiple Connection Denial Of Service Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
SpyNet Chat Server Multiple Connection Denial Of Service Vulnerability
References:
References: