PopMessenger Base64 encoding denial of service

popmessenger-base64-dos (17465) The risk level is classified as MediumMedium Risk

Description:

PopMessenger is vulnerable to a denial of service attack, caused by a vulnerability in the Base64 encoding. A remote attacker could create a specially-crafted message containing illegal characters and send it to a victim multiple times to cause PopMessenger to crash.


Consequences:

Denial of Service

Remedy:

Upgrade to the latest version of PopMessenger (1.60 dated after September 20, 2004 or later), available from the PopMessenger Web site. See References.

References:

  • BugTraq Mailing List, Tue Sep 21 2004 - 13:48:31 CDT : Broadcast crash in Popmessenger 1.60 (before 20 Sep 2004).
  • PopMessenger Web site: LAN chat software. Messenger for local network (LANs)..
  • BID-11230: LeadMind Pop Messenger Illegal Character Remote Denial Of Service Vulnerability
  • CVE-2004-1698: The Base64 function in PopMessenger 1.60 (before 20 Sep 2004) and earlier allows remote attackers to cause a denial of service (application crash) via invalid characters in a message, which causes several alert dialogs to be displayed and leads to a crash.
  • SA12612: Pop Messenger Invalid Character Denial of Service Vulnerability

Platforms Affected:

  • LeadMind Development PopMessenger 1.60 and prior

Reported:

Sep 21, 2004

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page