Vulnerabilities > CVE-2006-2555 - Remote Buffer Overflow and Denial Of Service vulnerability in Genecys

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
genecys
exploit available

Summary

The parse_command function in Genecys 0.2 and earlier allows remote attackers to cause a denial of service (crash) via a command with a missing ":" (colon) separator, which triggers a null dereference.

Vulnerable Configurations

Part Description Count
Application
Genecys
1

Exploit-Db

descriptionGenecys. CVE-2006-2554,CVE-2006-2555. Dos exploit for windows platform
idEDB-ID:1783
last seen2016-01-31
modified2006-05-14
published2006-05-14
reporterLuigi Auriemma
sourcehttps://www.exploit-db.com/download/1783/
titleGenecys <= 0.2 - BoF/NULL pointer Denial of Service Exploit