Exploitation Summary
EIP tracks 1 public exploit for CVE-2014-7222. PoCs published by SpyEye & Christian Galeon.
AI-analyzed exploit summary This exploit demonstrates a buffer overflow vulnerability in TeamSpeak Client v3.0.14 and earlier, causing a crash when malicious BBCode is sent in the chat/server tab. The PoC includes two variants (CVE-2014-7221 and CVE-2014-7222) that trigger the vulnerability via crafted image tags.
Description
Buffer overflow in TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (application crash) by connecting to a channel with a different client instance, and placing crafted data in the Chat/Server tab with two \\ (backslash) characters, a digit, a \ (backslash) character, and "z" in a series of nested img BBCODE tags.
Exploits (1)
This exploit demonstrates a buffer overflow vulnerability in TeamSpeak Client v3.0.14 and earlier, causing a crash when malicious BBCode is sent in the chat/server tab. The PoC includes two variants (CVE-2014-7221 and CVE-2014-7222) that trigger the vulnerability via crafted image tags.
References (5)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H