Roger Wilco服务器未授权音频流服务拒绝漏洞

Roger Wilco服务器未授权音频流服务拒绝漏洞

漏洞ID 1107839 漏洞类型 设计错误
发布时间 2004-03-31 更新时间 2005-10-20
图片[1]-Roger Wilco服务器未授权音频流服务拒绝漏洞-安全小百科CVE编号 CVE-2004-2451
图片[2]-Roger Wilco服务器未授权音频流服务拒绝漏洞-安全小百科CNNVD-ID CNNVD-200412-556
漏洞平台 Multiple CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/23904
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200412-556
|漏洞详情
RogerWilco1.4.1.6及其早期版本或RogerWilcoBaseStation0.30a及其早期版本存在漏洞。远程攻击者可以利用该漏洞向任意信道发送音频,也称为”Voicesfromthedeep”漏洞。
|漏洞EXP
source: http://www.securityfocus.com/bid/10025/info

A vulnerability has been reported in the Roger Wilco Server, it is reported that a user does not need to connect to the server over the TCP port to have UDP based audio streams handled. Rather the attacker will require knowledge of user ID's connected to a target channel. Because the user ID's for a channel exist in a range of 0-127, the attacker may transmit an audio stream to an affected server that will be heard by all connected users, however the server administrator will have no control over disconnecting or muting this audio stream. 

https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/bin-sploits/23904.zip
|参考资料

来源:XF
名称:roger-wilco-audio-access(15819)
链接:http://xforce.iss.net/xforce/xfdb/15819
来源:BID
名称:10025
链接:http://www.securityfocus.com/bid/10025
来源:SECUNIA
名称:11270
链接:http://secunia.com/advisories/11270
来源:BUGTRAQ
名称:20040331RogerWilco:newfunnybugs
链接:http://archives.neohapsis.com/archives/bugtraq/2004-03/0352.html

相关推荐: JWalk应用服务器文件泄漏漏洞

JWalk应用服务器文件泄漏漏洞 漏洞ID 1202124 漏洞类型 路径遍历 发布时间 2003-12-31 更新时间 2003-12-31 CVE编号 CVE-2003-1529 CNNVD-ID CNNVD-200312-428 漏洞平台 N/A CVS…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享