KaZaA广告应答远程拒绝服务攻击漏洞

KaZaA广告应答远程拒绝服务攻击漏洞

漏洞ID 1203102 漏洞类型 缓冲区溢出
发布时间 2003-02-03 更新时间 2003-12-31
图片[1]-KaZaA广告应答远程拒绝服务攻击漏洞-安全小百科CVE编号 CVE-2003-1395
图片[2]-KaZaA广告应答远程拒绝服务攻击漏洞-安全小百科CNNVD-ID CNNVD-200312-479
漏洞平台 N/A CVSS评分 9.0
|漏洞来源
https://cxsecurity.com/issue/WLB-2007100073
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200312-479
|漏洞详情
KaZaaMediaDesktop是第二代对等文件共享服务,利用该软件,您可以从其它KaZaa使用者那里,搜寻和下载媒体文件。KaZaA对广告应答缺少正确处理,远程攻击者可以利用这个漏洞对KaZaA客户端进行拒绝服务攻击。当KaZaA客户端与服务器端发起连接时,会产生广告下载请求,但是KaZaA不充分正确处理未预料的广告请求应答,恶意的响应可以导致KaZaA客户端崩溃。
|漏洞EXP
Hi!

It is possible to cause a remote denial of service attack against Kazaa
Media Desktop v2.

If you can inject a malicous response for the automated ad download of
the client, you can cause a bufferoverflow and the denial of service. It
may be possible to run arbitary code with this vulnerability.

The easiest way to reproduce this behavior is deny all http connections
to hosts named *ad*. For example activate the "Block Sites" feature of
the NetGear FM114P and block the keyword "ad". After this change, every
time you start the vulnerable Kazaa client, the software crashes with
the typical windows error message during connection establishment.

Tested on Kazaa Media Desktop 2.0.2, Built Tuesday, November 05, 2002,
17:07:24 on Windows XP Professional with NetGear FM114P.

My bug report was sent on 03/01/27 to The Sharman Networks Team. Nothing
came back - Just the automated default reply.

Bye, Marc

-- 
Computer, Technik und Security                  http://www.computec.ch/
Meine private Webseite                    http://www.computec.ch/mruef/
|参考资料

来源:XF
名称:kazaa-automated-ad-bo(11228)
链接:http://xforce.iss.net/xforce/xfdb/11228
来源:BID
名称:6747
链接:http://www.securityfocus.com/bid/6747
来源:BUGTRAQ
名称:20030202DenialofserviceagainstKazaaMediaDesktopv2
链接:http://www.securityfocus.com/archive/1/309935
来源:SREASON
名称:3252
链接:http://securityreason.com/securityalert/3252
来源:NSFOCUS
名称:4327
链接:http://www.nsfocus.net/vulndb/4327

相关推荐: Nuca WebServer File Disclosure Vulnerability

Nuca WebServer File Disclosure Vulnerability 漏洞ID 1100066 漏洞类型 Input Validation Error 发布时间 2003-06-10 更新时间 2003-06-10 CVE编号 N/A CN…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享