vendor:
Viber
by:
Mohammad Reza Espargham
7,8
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Viber
Affected Version From: Viber 4.2.0
Affected Version To: Viber 4.2.0
Patch Exists: YES
Related CWE: N/A
CPE: a:viber:viber
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: IOS 7.1.2
2014
Viber Non-Printable Characters Handling Denial of Service Vulnerability
Viber is prone to a denial-of-service vulnerability. An attacker can exploit this issue to cause denial-of-service condition, denying service to legitimate users. This issue is due to the application's failure to properly handle non-printable characters. An attacker can exploit this issue by sending a specially crafted message to the affected application. This issue affects Viber 4.2.0 on IOS 7.1.2.
Mitigation:
Upgrade to the latest version of Viber.