Vulnerabilities > CVE-2006-4126 - Denial of Service vulnerability in Dconnect Daemon 0.0.2/0.0.3/0.7.0

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
dconnect
exploit available

Summary

The dc_chat function in cmd.dc.c in DConnect Daemon 0.7.0 and earlier allows remote attackers to cause a denial of service (application crash) by sending a client message before providing the nickname, which triggers a null pointer dereference. This vulnerability is addressed in the following product release: DConnect, DConnect Daemon, 0.7.1

Vulnerable Configurations

Part Description Count
Application
Dconnect
3

Exploit-Db

descriptionDConnect Daemon DC Chat Denial of Service Vulnerability. CVE-2006-4126. Dos exploits for multiple platform
idEDB-ID:28345
last seen2016-02-03
modified2006-08-06
published2006-08-06
reporterLuigi Auriemma
sourcehttps://www.exploit-db.com/download/28345/
titleDConnect Daemon DC Chat Denial of Service Vulnerability