Vulnerabilities > CVE-2005-2719 - Denial Of Service vulnerability in Ventrilo Status Requests

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
flagship-industries
nessus
exploit available

Summary

Ventrilo 2.1.2 through 2.3.0 allows remote attackers to cause a denial of service (application crash) via a status packet that contains less data than specified in the packet header sent to UDP port 3784.

Exploit-Db

descriptionVentrilo <= 2.3.0 Remote Denial of Service Exploit (all platforms). CVE-2005-2719. Dos exploits for multiple platform
idEDB-ID:1176
last seen2016-01-31
modified2005-08-23
published2005-08-23
reporterLuigi Auriemma
sourcehttps://www.exploit-db.com/download/1176/
titleVentrilo <= 2.3.0 - Remote Denial of Service Exploit all platforms

Nessus

NASL familyDenial of Service
NASL idVENTRILO_DOS.NASL
descriptionA malicious user can crash the remote version of Ventrilo due to a vulnerability in the way the server handles malformed status queries.
last seen2020-06-01
modified2020-06-02
plugin id19757
published2005-09-19
reporterCopyright (C) 2005-2018 Josh Zlatin-Amishav
sourcehttps://www.tenable.com/plugins/nessus/19757
titleVentrilo Server Malformed Status Query Remote DoS