Speak Freely <= 7.6a DoS
Auriemma Luigi <[email protected]>
| Newsgroups | gmane.comp.audio.speak-freely.general |
|---|---|
| Message-ID | <[email protected]> |
Hey to all
As any other program for real-time voice, also Speak Freely uses UDP
datagram.
The problem is that everyone that can spoof his own packets can establish a
lot of connections to a listening Speak Freely host until it consumes all
its resources.
That's just what happens on the Windows version of the program that will
crash when an attacker will send less than 200 spoofed UDP datagrams.
I have also tested the Linux version and the program Xsf but they are NOT
vulnerable.
I have already written an exploit (runs from Linux) and I can provide it if
you want (I can upload it on my website).
Let me know if you need more informations.
BYEZ
P.S. = I hope that's the right place to signal security bugs.
---
Researcher
http://www.pivx.com/luigi/
* * *
To unsubscribe from this mailing list, send E-mail containing
the word "unsubscribe" in the message body (*not* as the
Subject) to [email protected]