vendor:
ChatZilla
by:
m00 Security
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: ChatZilla
Affected Version From: 2000.8.23
Affected Version To: 2000.8.23
Patch Exists: YES
Related CWE: N/A
CPE: o:mozilla:chatzilla
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2003
ChatZilla <=v0.8.23 remote DoS exploit
It has been reported that ChatZilla is prone to a denial of service vulnerability. The problem arises as a remote attacker posing as an IRC server sends specially crafted requests to the client containing large strings. If successful, an attack would lead to a denial of service in the client software.
Mitigation:
Ensure that the latest version of ChatZilla is installed and running.