Surfnet CMD_CREDITCARD_CHARGE Denial Of Service Vulnerability
BID:9348
Info
Surfnet CMD_CREDITCARD_CHARGE Denial Of Service Vulnerability
| Bugtraq ID: | 9348 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 02 2004 12:00AM |
| Updated: | Jan 02 2004 12:00AM |
| Credit: | Discovery is credited to <[email protected]>. |
| Vulnerable: |
Info Touch Surfnet 1.31 |
| Not Vulnerable: | |
Discussion
Surfnet CMD_CREDITCARD_CHARGE Denial Of Service Vulnerability
Surfnet is prone to a denial of service vulnerability via the CMD_CREDITCARD_CHARGE command. By issuing this command with malformed arguments, it is possible to crash the software. When the software crashes, it will drop the kiosk user into the underlying operating system.
Surfnet is prone to a denial of service vulnerability via the CMD_CREDITCARD_CHARGE command. By issuing this command with malformed arguments, it is possible to crash the software. When the software crashes, it will drop the kiosk user into the underlying operating system.
Exploit / POC
Solution / Fix
Surfnet CMD_CREDITCARD_CHARGE Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Surfnet CMD_CREDITCARD_CHARGE Denial Of Service Vulnerability
References:
References:
- Surfnet Homepage (Info Touch)