vendor:
KaZaA
by:
Josh and omega
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: KaZaA
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
KaZaA Denial of Service Attack
KaZaA may consume large amounts of CPU when processing a sequence of large messages. It is possible for an attacker to flood a vulnerable system with a large number of messages, resulting in a denial of service condition.
Mitigation:
Limit the number of messages that can be sent to the system and ensure that the system is not exposed to the public internet.