lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Wed, 15 Aug 2007 00:18:09 +0200 From: Luigi Auriemma <aluigi@...istici.org> To: bugtraq@...urityfocus.com, bugs@...uritytracker.com, news@...uriteam.com, full-disclosure@...ts.grok.org.uk, vuln@...unia.com, packet@...ketstormsecurity.org Subject: Crash in Zoidcom 0.6.7 ####################################################################### Luigi Auriemma Application: Zoidcom http://www.zoidcom.com Versions: <= 0.6.7 (some older version could be not vulnerable) Platforms: Windows, Linux and Mac Bug: crash Exploitation: remote Date: 14 Aug 2007 Author: Luigi Auriemma e-mail: aluigi@...istici.org web: aluigi.org ####################################################################### 1) Introduction 2) Bug 3) The Code 4) Fix ####################################################################### =============== 1) Introduction =============== Zoidcom is an interesting network library studied for the minimal usage of bandwidth. ####################################################################### ====== 2) Bug ====== The library can be crashed remotely through a malformed connection packet which forces the code to perform a double-delete of the data used for tracing the connection. ####################################################################### =========== 3) The Code =========== http://aluigi.org/poc/zoidboom2.zip ####################################################################### ====== 4) Fix ====== the bug will be fixed in version 0.6.8 ####################################################################### --- Luigi Auriemma http://aluigi.org http://mirror.aluigi.org _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists