| VID |
22331 |
| Severity |
20 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
WWW |
| Detailed Description |
The BadBlue server, according to its banner, has a denial of service vulnerability via a large number of connections. BadBlue is a P2P file sharing Web server distributed by Working Resources for Microsoft Windows operating systems. BadBlue versions 2.52 and earlier are vulnerable to a denial of service attack. By establishing approximately 24 concurrent connections to a vulnerable Web server from the same host, a remote attacker could cause the Web server to deny all incoming HTTP requests.
* Note: This check solely relied on the banner of the remote HTTP server to assess this vulnerability, so this might be a false positive.
* References: http://www.securityfocus.com/archive/1/372470
* Platforms Affected: Working Resources Inc., BadBlue Enterprise Edition 2.52 and earlier Working Resources Inc., BadBlue Personal Edition 2.52 and earlier Microsoft Windows Any version |
| Recommendation |
Upgrade to the latest version of BadBlue (2.61 or later), available from the BadBlue Download Web site at http://www.badblue.com/down.htm |
| Related URL |
CVE-2004-1727 (CVE) |
| Related URL |
10983 (SecurityFocus) |
| Related URL |
17064 (ISS) |
|