vendor:
Desktop Orbiter
by:
Luca Ercoli
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Desktop Orbiter
Affected Version From: 02.01
Affected Version To: 02.01
Patch Exists: NO
Related CWE: N/A
CPE: a:desktop_orbiter:desktop_orbiter:2.01
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
Desktop Orbiter 2.01 Denial of Service
A denial of service vulnerability has been reported for Desktop Orbiter. The vulnerability exists due to the way the application handles connections. Specifically, for every open connection, a snapshot preview of the desktop is loaded into memory. Thus, numerous connections would result in a consumption of all available memory resources.
Mitigation:
Limit the number of connections to the application.