Communigate Pro Web Admin DoS Vulnerability
BID:860
Info
Communigate Pro Web Admin DoS Vulnerability
| Bugtraq ID: | 860 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Dec 03 1999 12:00AM |
| Updated: | Dec 03 1999 12:00AM |
| Credit: | Posted to Bugtraq on December 3, 1999 by Nobuo Miwa <[email protected]>. |
| Vulnerable: |
Stalker Communigate Pro 3.1 |
| Not Vulnerable: |
Stalker Communigate Pro 3.2 b7 Stalker Communigate Pro 3.2 b5 |
Discussion
Communigate Pro Web Admin DoS Vulnerability
Communigate Pro 3.1 can be remotely crashed due to a weakness in the remote administration feature. Connecting to port 8010 (the web admin port) and sending a buffer of 70000 characters , then connecting to any other port on the server, will cause the server to crash.
Communigate Pro 3.1 can be remotely crashed due to a weakness in the remote administration feature. Connecting to port 8010 (the web admin port) and sending a buffer of 70000 characters , then connecting to any other port on the server, will cause the server to crash.
Exploit / POC
Communigate Pro Web Admin DoS Vulnerability
see discussion
see discussion
Solution / Fix
Communigate Pro Web Admin DoS Vulnerability
Solution:
Fixed in the latest beta releases of 3.2, 3.2b5 and 3.2b7, available from:
ftp://ftp.stalker.com/pub/CommuniGatePro/
Solution:
Fixed in the latest beta releases of 3.2, 3.2b5 and 3.2b7, available from:
ftp://ftp.stalker.com/pub/CommuniGatePro/