CVE Database
/

CVE-2007-5030

Back to search

CVE-2007-5030

Published: Sep 21, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple integer overflows in Dibbler 0.6.0 allow remote attackers to cause a denial of service (daemon crash) via packets containing options with large lengths, which trigger attempts at excessive memory allocation, as demonstrated by (1) the TSrvMsg constructor in SrvMessages/SrvMsg.cpp; the (2) TClntMsg, (3) TClntOptIAAddress, (4) TClntOptIAPrefix, (5) TOptVendorSpecInfo, and (6) TOptOptionRequest constructors; and the (7) TRelIfaceMgr::decodeRelayRepl, (8) TRelMsg::decodeOpts, and (9) TSrvIfaceMgr::decodeRelayForw methods.

VendorProductVersions

n/a

n/a

affected
n/a

References

dibbler-optionlength-dos(36684)
vdb-entry
x_refsource_XF
40568
vdb-entry
x_refsource_OSVDB
26876
third-party-advisory
x_refsource_SECUNIA
25726
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now