vendor:
Really Simple IM
by:
loneferret
7,5
CVSS
HIGH
Denial of Service (DoS)
400
CWE
Product Name: Really Simple IM
Affected Version From: 1.3 beta
Affected Version To: 1.3 beta
Patch Exists: YES
Related CWE: N/A
CPE: a:reallysimpleim:really_simple_im:1.3beta
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP Professional SP2-SP3 & Windows XP Home SP3
2010
DoS proof of concept
This proof of concept exploits a vulnerability in Really Simple IM version 1.3 beta, which uses UDP to send and receive messages. It broadcasts everything, and picks up everything on port 54533. The exploit sends a 'p' command with a buffer of 'W00T' followed by 10000 'A' characters, which causes all clients in the same subnet to crash.
Mitigation:
Upgrade to the latest version of Really Simple IM.