vendor:
Bird Chat
by:
Donato Ferrante
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Bird Chat
Affected Version From: 1.61
Affected Version To: 1.61
Patch Exists: YES
Related CWE: N/A
CPE: a:bird_chat:bird_chat:1.61
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
Bird Chat 1.61 – Denial Of Service – Proof Of Concept
This proof of concept code exploits a denial of service vulnerability in Bird Chat 1.61. The code attempts to establish multiple connections to the target server, sending a fake user name with each connection. If the server is vulnerable, it will not respond to the connection and the connection will time out. If the server is not vulnerable, it will respond with a '?' character.
Mitigation:
Upgrade to the latest version of Bird Chat.