SILC Server INVITE Command Double Free Heap Corruption Vulnerability
BID:6730
Info
SILC Server INVITE Command Double Free Heap Corruption Vulnerability
| Bugtraq ID: | 6730 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 29 2003 12:00AM |
| Updated: | Jan 29 2003 12:00AM |
| Credit: | This issue was announced in the product changelog. |
| Vulnerable: |
SILC Secure Internet Live Conferencing 0.9.11 |
| Not Vulnerable: |
SILC Secure Internet Live Conferencing 0.9.12 |
Discussion
SILC Server INVITE Command Double Free Heap Corruption Vulnerability
SILC Server is prone to a double free heap corruption vulnerability in error logging of the 'INVITE' command.
Successful exploitation of this vulnerability may result in a denial of service attack via heap memory corruption. It is not known whether this issue is exploitable to execute arbitrary code.
SILC Server is prone to a double free heap corruption vulnerability in error logging of the 'INVITE' command.
Successful exploitation of this vulnerability may result in a denial of service attack via heap memory corruption. It is not known whether this issue is exploitable to execute arbitrary code.
Exploit / POC
SILC Server INVITE Command Double Free Heap Corruption Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
SILC Server INVITE Command Double Free Heap Corruption Vulnerability
References:
References:
- SILC Webpage (SILC)