This application requires Javascript for optimal performance.

Ventrilo.Status.Requests.DoS

Release Date

Jan 04, 2007

Severity

low

Impact

Denial of service.

Description

It indicates a possible exploit of a DoS vulnerability in Ventrilo, that may allow remote attackers to cause a denial of service (application crash) via a status packet that contains less data than specified in the packet header sent to UDP port 3784.

Affected Products

Flagship Industries Ventrilo 2.3
Flagship Industries Ventrilo 2.2
Flagship Industries Ventrilo 2.1.4
Flagship Industries Ventrilo 2.1.3
Flagship Industries Ventrilo 2.1.2

Recommended Actions

Currently we are not aware of any vendor-supplied patches for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2005-2719

Reference/s

http://www.securityfocus.com/bid/14644 (BugTraq)
http://aluigi.altervista.org/poc/ventboom.zip

Reference: VID-13740