|
|
| |
| The Timbuktu software is shipped as "a client/server application that allows remote users to access the desktop of a host system". The server component of this application is vulnerable to a remote buffer overflow vulnerability that, when exploited, causes the server process to crash. |
| |
Credit:
The information has been provided by Stephen de Vries.
|
| |
Vulnerable Systems:
* Timbuktu version 7.0.3
Immune Systems:
* Timbuktu version 7.0.4
The server process runs with root privileges on the host Mac OS X and listens for client connections on TCP port 407. By making a number of concurrent connections to this port and repeatedly sending a particular string of data, a memory buffer is overwritten and the server process crashes.
CVE Information:
CAN-2004-0810
|
|
|