Xlpd Remote Denial of Service Vulnerability
BID:36610
Info
Xlpd Remote Denial of Service Vulnerability
| Bugtraq ID: | 36610 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 07 2009 12:00AM |
| Updated: | Oct 07 2009 08:29PM |
| Credit: | Francis Provencher from Protek Research Labs |
| Vulnerable: |
NetSarang Xlpd 3.0 |
| Not Vulnerable: | |
Discussion
Xlpd Remote Denial of Service Vulnerability
Xlpd is prone to a denial-of-service vulnerability because it fails to adequately validate user-supplied input.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users. Given the nature of this issue, the attacker may also be able to run arbitrary code, but this has not been confirmed.
Xlpd 3.0 is vulnerable; other versions may also be affected.
Xlpd is prone to a denial-of-service vulnerability because it fails to adequately validate user-supplied input.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users. Given the nature of this issue, the attacker may also be able to run arbitrary code, but this has not been confirmed.
Xlpd 3.0 is vulnerable; other versions may also be affected.
Exploit / POC
Xlpd Remote Denial of Service Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Xlpd Remote Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Xlpd Remote Denial of Service Vulnerability
References:
References:
- Xlpd Homepage (NetSarang)
- {PRL} XLPD 3.0 Remote DoS (Protek Research Lab
)