CVE-2008-3680
14.08.2008, 19:41
The decryption function in Flagship Industries Ventrilo 3.0.2 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) by sending a type 0 packet with an invalid version followed by another packet to TCP port 3784.Enginsight
Vendor | Product | Version |
---|---|---|
flagship_industries | ventrilo | 1.01 |
flagship_industries | ventrilo | 1.03 |
flagship_industries | ventrilo | 1.04 |
flagship_industries | ventrilo | 1.05 |
flagship_industries | ventrilo | 1.06 |
flagship_industries | ventrilo | 2.1 |
flagship_industries | ventrilo | 2.1.1 |
flagship_industries | ventrilo | 2.1.2 |
flagship_industries | ventrilo | 2.1.3 |
flagship_industries | ventrilo | 2.1.4 |
flagship_industries | ventrilo | 2.2 |
flagship_industries | ventrilo | 2.3 |
flagship_industries | ventrilo | 2.3.2:prototype.6 |
flagship_industries | ventrilo | 2.3.2:prototype.9 |
flagship_industries | ventrilo | 3.0.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References