bugs.gentoo.org
http://bugs.gentoo.org/show_bug.cgi?id=200110 CVE-2007-5824
Firefly Media Server 0.2.4 - Remote Denial of Service
Record summary
CVE-2007-5824 has a selected CVSS score of 7.1; EIP currently links 1 catalogued exploit.
Description
webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a stats method action to /xml-rpc with (1) an empty Authorization header line, which triggers a crash in the ws_decodepassword function; or (2) a header line without a ':' character, which triggers a crash in the ws_getheaders function.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBFirefly Media Server 0.2.4 - Remote Denial of ServiceExploitDB exploitby nnpNot analyzed1 file
References
Showing 12 of 1428269Third-party advisory
http://secunia.com/advisories/28269 30661Third-party advisory
http://secunia.com/advisories/30661 sourceforge.netConfirmation
http://sourceforge.net/project/shownotes.php?group_id=98211&release_id=548679 DSA-1597Vendor advisory
http://www.debian.org/security/2008/dsa-1597 GLSA-200712-18Vendor advisory
http://www.gentoo.org/security/en/glsa/glsa-200712-18.xml 20071102 [UPH-07-01] Firefly Media Server DoSmailing list
http://www.securityfocus.com/archive/1/483210/100/0/threaded 20071102 [UPH-07-02] Firefly Media Server DoSmailing list
http://www.securityfocus.com/archive/1/483211/100/0/threaded 20071102 Re: [UPH-07-01] Firefly Media Server DoSmailing list
http://www.securityfocus.com/archive/1/483215/100/0/threaded 26309vdb entry
http://www.securityfocus.com/bid/26309 firefly-getheaders-dos(38241)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/38241 firefly-decodepassword-dos(38242)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/38242