Network Service Malformed Data Remote DoS

high Nessus Plugin ID 17296

Synopsis

The remote service is potentially vulnerable to a denial of service attack.

Description

It appears to be possible to crash the remote service by sending it a few kilobytes of random data.

An attacker may use this flaw to make this service crash continuously, preventing this service from working properly. It may also be possible to exploit this flaw to execute arbitrary code on this host.

Solution

Upgrade your software or contact your vendor to inform them of this potential vulnerability.

Plugin Details

Severity: High

ID: 17296

File Name: random_crap_DoS.nasl

Version: 1.21

Type: remote

Published: 3/8/2005

Updated: 5/3/2023

Supported Sensors: Nessus

Risk Information

CVSS Score Rationale: Score based on manual analysis of potential vulnerability.

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 6.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:C

CVSS Score Source: manual

CVSS v3

Risk Factor: High

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 4/27/1999

Reference Information

CVE: CVE-1999-1196

BID: 158