20050909 Zebedee DoS Vulnerabilitymailing list
http://marc.info/?l=bugtraq&m=112629543605488&w=2 CVE-2005-2904
Zebedee 2.4.1 - Remote Denial of Service
Record summary
CVE-2005-2904 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
Zebedee 2.4.1, when "allowed redirection port" is not set, allows remote attackers to cause a denial of service (application crash) via a zero in the port number of the protocol option header, which triggers an assert error in the makeConnection function in zebedee.c.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBZebedee 2.4.1 - Remote Denial of ServiceExploitDB exploitby Shiraishi.MNot analyzed1 file
References
516788Third-party advisory
http://secunia.com/advisories/16788 GLSA-200509-14Vendor advisory
http://www.gentoo.org/security/en/glsa/glsa-200509-14.xml 14796vdb entry
http://www.securityfocus.com/bid/14796 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2005-2904