SILC Server 'NEW_CLIENT' Remote Denial of Service Vulnerability
BID:28450
Info
SILC Server 'NEW_CLIENT' Remote Denial of Service Vulnerability
| Bugtraq ID: | 28450 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-1429 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 14 2008 12:00AM |
| Updated: | Apr 24 2008 09:27PM |
| Credit: | SILC |
| Vulnerable: |
SILC Server 1.1 Gentoo Linux |
| Not Vulnerable: |
SILC Server 1.1.2 SILC Server 1.1.1 |
Discussion
SILC Server 'NEW_CLIENT' Remote Denial of Service Vulnerability
SILC Server is prone to a remote denial-of-service vulnerability because the application fails to properly handle exceptional conditions.
Successfully exploiting this issue allows remote attackers to crash the application, denying service to legitimate users.
This issue affects versions prior to SILC Server 1.1.1.
SILC Server is prone to a remote denial-of-service vulnerability because the application fails to properly handle exceptional conditions.
Successfully exploiting this issue allows remote attackers to crash the application, denying service to legitimate users.
This issue affects versions prior to SILC Server 1.1.1.
Exploit / POC
SILC Server 'NEW_CLIENT' Remote Denial of Service Vulnerability
The attacker can use readily available tools to craft a malicious packet and exploit this issue.
The attacker can use readily available tools to craft a malicious packet and exploit this issue.
Solution / Fix
SILC Server 'NEW_CLIENT' Remote Denial of Service Vulnerability
Solution:
The vendor has released updates. Please see the references for more information.
Solution:
The vendor has released updates. Please see the references for more information.
References
SILC Server 'NEW_CLIENT' Remote Denial of Service Vulnerability
References:
References:
- SILC Server 1.1.1 Release Notes (SILC)
- SILC Webpage (SILC)