5
CVSSv2

CVE-2004-1792

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

swnet.dll in YaSoft Switch Off 2.3 and previous versions allows remote malicious users to cause a denial of service (infinite loop) via a long packet with two CRLF sequences to the service management port (TCP 8000).

Vulnerable Product Search on Vulmon Subscribe to Product

yatsoft switch off 0.7

yatsoft switch off 1.5.1

yatsoft switch off 1.6

yatsoft switch off 2.3

yatsoft switch off 1.2

yatsoft switch off 1.3

yatsoft switch off 1.9

yatsoft switch off 2.0

yatsoft switch off 1.4

yatsoft switch off 1.5

yatsoft switch off 2.1

yatsoft switch off 2.2

yatsoft switch off 1.0

yatsoft switch off 1.1

yatsoft switch off 1.7

yatsoft switch off 1.8

Exploits

source: wwwsecurityfocuscom/bid/9339/info A problem has been identified in the YaSoft Switch Off software package when handling large packets via the service management port (8000/TCP) This may make it possible for a remote user to deny service to legitimate users of the service perl -e "print 'a'x10240 chr(0x0d)chr(0x0a)chr(0x0d) ...