vendor:
Blubster
by:
Luca Ercoli
7.5
CVSS
HIGH
Port Flooding Attack
400
CWE
Product Name: Blubster
Affected Version From: 2.5
Affected Version To: 2.5
Patch Exists: NO
Related CWE: N/A
CPE: a:blubster:blubster:2.5
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
Blubster client v2.5 Remote Denial of Service
It has been reported that Blubster is prone to a remote denial of service vulnerability due to a port flooding attack on TCP port 701. The problem is reported to present itself when a remote attacker floods port 701 with voice chat session requests. This issue may cause the software to crash resulting in a denial of service to legitimate users. This attack may not be logged, therefore allowing an attack to exploit this issue persistently.
Mitigation:
Limit the number of requests to the port, or block the port altogether.