CVE-2013-3986
IBM Lotus Sametime 8.5.2-8.5.2.1 - Denial of Service via Crafted Audio Visual Session
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-3986.
PoCs published by Chris John Riley, kicks4kittens, including Metasploit module auxiliary/dos/misc/ibm_sametime_webplayer_dos.
AI-analyzed exploit summary This Metasploit module exploits a denial-of-service vulnerability in IBM Lotus Sametime WebPlayer by sending a maliciously crafted SIP MESSAGE packet with an oversized payload to crash the target user's WebPlayer plugin.
Description
IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote attackers to cause a denial of service (WebPlayer Firefox extension crash) via a crafted Audio Visual (AV) session.
Exploits (1)
This Metasploit module exploits a denial-of-service vulnerability in IBM Lotus Sametime WebPlayer by sending a maliciously crafted SIP MESSAGE packet with an oversized payload to crash the target user's WebPlayer plugin.