xfstt Denial Of Service Vulnerability
BID:8182
Info
xfstt Denial Of Service Vulnerability
| Bugtraq ID: | 8182 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0581 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 14 2003 12:00AM |
| Updated: | Jul 11 2009 10:56PM |
| Credit: | Disclosure credited to Jonathan Heusser. |
| Vulnerable: |
xfstt xfstt 1.4 xfstt xfstt 1.2.1 |
| Not Vulnerable: | |
Discussion
xfstt Denial Of Service Vulnerability
It has been reported that attackers may be able to crash an xfstt server by sending it a specially malformed packet. Reportedly, the working() function may not properly perform bounds checking on incoming packets prior to parsing headers and storing information in internal buffers. This may allow arbitrary data to be written to adjacent memory locations, possibly resulting in a denial of service condition against the server.
It has been reported that attackers may be able to crash an xfstt server by sending it a specially malformed packet. Reportedly, the working() function may not properly perform bounds checking on incoming packets prior to parsing headers and storing information in internal buffers. This may allow arbitrary data to be written to adjacent memory locations, possibly resulting in a denial of service condition against the server.
Exploit / POC
xfstt Denial Of Service Vulnerability
It has been reported that a functional exploit for this vulnerability exists, but is not publicly available. It is also likely that this issue could be exploited with any number of available packet shaping tools.
It has been reported that a functional exploit for this vulnerability exists, but is not publicly available. It is also likely that this issue could be exploited with any number of available packet shaping tools.
References
xfstt Denial Of Service Vulnerability
References:
References:
- Project Information (xfstt)
- xfstt-1.4 vulnerability (ruben unteregger
)