CVE-2008-3680

The decryption function in Flagship Industries Ventrilo 3.0.2 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) by sending a type 0 packet with an invalid version followed by another packet to TCP port 3784.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:flagship_industries:ventrilo:1:*:*:*:*:*:*:*
cpe:2.3:a:flagship_industries:ventrilo:1.01:*:*:*:*:*:*:*
cpe:2.3:a:flagship_industries:ventrilo:1.03:*:*:*:*:*:*:*
cpe:2.3:a:flagship_industries:ventrilo:1.04:*:*:*:*:*:*:*
cpe:2.3:a:flagship_industries:ventrilo:1.05:*:*:*:*:*:*:*
cpe:2.3:a:flagship_industries:ventrilo:1.06:*:*:*:*:*:*:*
cpe:2.3:a:flagship_industries:ventrilo:2:*:*:*:*:*:*:*
cpe:2.3:a:flagship_industries:ventrilo:2.1:*:*:*:*:*:*:*
cpe:2.3:a:flagship_industries:ventrilo:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:flagship_industries:ventrilo:2.1.2:*:*:*:*:*:*:*
cpe:2.3:a:flagship_industries:ventrilo:2.1.3:*:*:*:*:*:*:*
cpe:2.3:a:flagship_industries:ventrilo:2.1.4:*:*:*:*:*:*:*
cpe:2.3:a:flagship_industries:ventrilo:2.2:*:*:*:*:*:*:*
cpe:2.3:a:flagship_industries:ventrilo:2.3:*:*:*:*:*:*:*
cpe:2.3:a:flagship_industries:ventrilo:2.3.2:prototype.6:*:*:*:*:*:*
cpe:2.3:a:flagship_industries:ventrilo:2.3.2:prototype.9:*:*:*:*:*:*
cpe:2.3:a:flagship_industries:ventrilo:3:*:*:*:*:*:*:*
cpe:2.3:a:flagship_industries:ventrilo:3.0.2:*:*:*:*:*:*:*

History

21 Nov 2024, 00:49

Type Values Removed Values Added
References () http://aluigi.altervista.org/adv/ventrilobotomy-adv.txt - () http://aluigi.altervista.org/adv/ventrilobotomy-adv.txt -
References () http://aluigi.org/poc/ventrilobotomy.zip - Exploit () http://aluigi.org/poc/ventrilobotomy.zip - Exploit
References () http://secunia.com/advisories/31466 - Vendor Advisory () http://secunia.com/advisories/31466 - Vendor Advisory
References () http://secunia.com/advisories/34696 - () http://secunia.com/advisories/34696 -
References () http://security.gentoo.org/glsa/glsa-200904-13.xml - () http://security.gentoo.org/glsa/glsa-200904-13.xml -
References () http://securityreason.com/securityalert/4156 - () http://securityreason.com/securityalert/4156 -
References () http://www.securityfocus.com/archive/1/495448/100/0/threaded - () http://www.securityfocus.com/archive/1/495448/100/0/threaded -
References () http://www.securityfocus.com/bid/30675 - Exploit () http://www.securityfocus.com/bid/30675 - Exploit
References () http://www.vupen.com/english/advisories/2008/2365 - () http://www.vupen.com/english/advisories/2008/2365 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/44428 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/44428 -
References () https://www.exploit-db.com/exploits/6237 - () https://www.exploit-db.com/exploits/6237 -

Information

Published : 2008-08-14 19:41

Updated : 2024-11-21 00:49


NVD link : CVE-2008-3680

Mitre link : CVE-2008-3680

CVE.ORG link : CVE-2008-3680


JSON object : View

Products Affected

flagship_industries

  • ventrilo
CWE
CWE-20

Improper Input Validation