CVE-2007-0614
iChat 3.1.6 - Denial of Service via Crafted Bonjour TXT Key
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0614.
AI-analyzed exploit summary This Ruby script exploits a design weakness in iChat Bonjour services by registering multiple fake _presence records, causing a denial of service (DoS) or triggering a SIGTRAP signal via a crafted TXT key hash. It demonstrates two attack methods: flooding with fake presence records and crashing iChat Agent with malformed data.
Description
The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (persistent application crash) via a crafted phsh hash attribute in a TXT key.
Exploits (1)
This Ruby script exploits a design weakness in iChat Bonjour services by registering multiple fake _presence records, causing a denial of service (DoS) or triggering a SIGTRAP signal via a crafted TXT key hash. It demonstrates two attack methods: flooding with fake presence records and crashing iChat Agent with malformed data.