Kroum Grigorov KpyM Telnet Server Remote Denial Of Service Vulnerability
BID:9379
Info
Kroum Grigorov KpyM Telnet Server Remote Denial Of Service Vulnerability
| Bugtraq ID: | 9379 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 07 2004 12:00AM |
| Updated: | Jan 07 2004 12:00AM |
| Credit: | The disclosure of this issue has been credited to NoRpiUs. |
| Vulnerable: |
Kroum Grigorov KpyM Telnet Server 1.0 5 Kroum Grigorov KpyM Telnet Server 1.0 4 Kroum Grigorov KpyM Telnet Server 1.0 3 Kroum Grigorov KpyM Telnet Server 1.0 2 Kroum Grigorov KpyM Telnet Server 1.0 1 Kroum Grigorov KpyM Telnet Server 1.0 |
| Not Vulnerable: |
Kroum Grigorov KpyM Telnet Server 1.0 6 |
Discussion
Kroum Grigorov KpyM Telnet Server Remote Denial Of Service Vulnerability
KpyM Telnet Server has been reported to be prone to a remote denial of service vulnerability. Due to a lack of resource limitations, a remote attacker may negotiate multiple connections to the affected server. This will cause multiple instances of the a terminal handler executable to be spawned and ultimately, over time, an access violation will be triggered in the KpyM Telnet Server.
KpyM Telnet Server has been reported to be prone to a remote denial of service vulnerability. Due to a lack of resource limitations, a remote attacker may negotiate multiple connections to the affected server. This will cause multiple instances of the a terminal handler executable to be spawned and ultimately, over time, an access violation will be triggered in the KpyM Telnet Server.
Exploit / POC
Kroum Grigorov KpyM Telnet Server Remote Denial Of Service Vulnerability
The following proof of concept has been supplied:
The following proof of concept has been supplied:
Solution / Fix
Kroum Grigorov KpyM Telnet Server Remote Denial Of Service Vulnerability
Solution:
The vendor has released KpyM version 1.06 to address this issue. Users are advised to download the fixed version.
Kroum Grigorov KpyM Telnet Server 1.0 2
Kroum Grigorov KpyM Telnet Server 1.0 4
Kroum Grigorov KpyM Telnet Server 1.0
Kroum Grigorov KpyM Telnet Server 1.0 3
Kroum Grigorov KpyM Telnet Server 1.0 5
Kroum Grigorov KpyM Telnet Server 1.0 1
Solution:
The vendor has released KpyM version 1.06 to address this issue. Users are advised to download the fixed version.
Kroum Grigorov KpyM Telnet Server 1.0 2
-
Kroum Grigorov kts106s.zip
http://osdn.dl.sourceforge.net/sourceforge/kpym/kts106s.zip
Kroum Grigorov KpyM Telnet Server 1.0 4
-
Kroum Grigorov kts106s.zip
http://osdn.dl.sourceforge.net/sourceforge/kpym/kts106s.zip
Kroum Grigorov KpyM Telnet Server 1.0
-
Kroum Grigorov kts106s.zip
http://osdn.dl.sourceforge.net/sourceforge/kpym/kts106s.zip
Kroum Grigorov KpyM Telnet Server 1.0 3
-
Kroum Grigorov kts106s.zip
http://osdn.dl.sourceforge.net/sourceforge/kpym/kts106s.zip
Kroum Grigorov KpyM Telnet Server 1.0 5
-
Kroum Grigorov kts106s.zip
http://osdn.dl.sourceforge.net/sourceforge/kpym/kts106s.zip
Kroum Grigorov KpyM Telnet Server 1.0 1
-
Kroum Grigorov kts106s.zip
http://osdn.dl.sourceforge.net/sourceforge/kpym/kts106s.zip
References
Kroum Grigorov KpyM Telnet Server Remote Denial Of Service Vulnerability
References:
References:
- Homepage (NoRpiUs)
- KpyM Telnet Server Homepage (Kroum Grigorov)