Speak Freely <= 7.6a DoS

Auriemma Luigi <[email protected]>
Newsgroups gmane.comp.audio.speak-freely.general
Message-ID <[email protected]>
Hey to all


As any other program for real-time voice, also Speak Freely uses UDP
datagram.

The problem is that everyone that can spoof his own packets can establish a
lot of connections to a listening Speak Freely host until it consumes all
its resources.
That's just what happens on the Windows version of the program that will
crash when an attacker will send less than 200 spoofed UDP datagrams.

I have also tested the Linux version and the program Xsf but they are NOT
vulnerable.

I have already written an exploit (runs from Linux) and I can provide it if
you want (I can upload it on my website).

Let me know if you need more informations.



BYEZ



P.S. = I hope that's the right place to signal security bugs.




--- 
Researcher
http://www.pivx.com/luigi/



                      * * *

To unsubscribe from this mailing list, send E-mail containing
the word "unsubscribe" in the message body (*not* as the
Subject) to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.