Vulnerabilities > CVE-2005-3694 - Remote Denial of Service vulnerability in Centericq 4.20.0R3

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE
network
low complexity
centericq
nessus
exploit available

Summary

centericq 4.20.0-r3 with "Enable peer-to-peer communications" set allows remote attackers to cause a denial of service (segmentation fault and crash) via short zero-length packets, and possibly packets of length 1 or 2, as demonstrated using Nessus.

Vulnerable Configurations

Part Description Count
Application
Centericq
1

Exploit-Db

descriptionCenterICQ 4.20/4.5 Malformed Packet Handling Remote Denial of Service Vulnerability. CVE-2005-3694. Dos exploit for linux platform
idEDB-ID:26666
last seen2016-02-03
modified2005-11-29
published2005-11-29
reporterWernfried Haas
sourcehttps://www.exploit-db.com/download/26666/
titleCenterICQ 4.20/4.5 Malformed Packet Handling Remote Denial of Service Vulnerability

Nessus

  • NASL familyGentoo Local Security Checks
    NASL idGENTOO_GLSA-200512-11.NASL
    descriptionThe remote host is affected by the vulnerability described in GLSA-200512-11 (CenterICQ: Multiple vulnerabilities) Gentoo developer Wernfried Haas discovered that when the
    last seen2020-06-01
    modified2020-06-02
    plugin id20352
    published2005-12-30
    reporterThis script is Copyright (C) 2005-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/20352
    titleGLSA-200512-11 : CenterICQ: Multiple vulnerabilities
  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-912.NASL
    descriptionWernfried Haas discovered that centericq, a text-mode multi-protocol instant messenger client, can crash when it receives certain zero length packets and is directly connected to the Internet.
    last seen2020-06-01
    modified2020-06-02
    plugin id22778
    published2006-10-14
    reporterThis script is Copyright (C) 2006-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/22778
    titleDebian DSA-912-1 : centericq - denial of service