Korean
<< Back
VID 22331
Severity 20
Port 80, ...
Protocol TCP
Class WWW
Detailed Description The BadBlue server, according to its banner, has a denial of service vulnerability via a large number of connections. BadBlue is a P2P file sharing Web server distributed by Working Resources for Microsoft Windows operating systems. BadBlue versions 2.52 and earlier are vulnerable to a denial of service attack. By establishing approximately 24 concurrent connections to a vulnerable Web server from the same host, a remote attacker could cause the Web server to deny all incoming HTTP requests.

* Note: This check solely relied on the banner of the remote HTTP server to assess this vulnerability, so this might be a false positive.

* References:
http://www.securityfocus.com/archive/1/372470

* Platforms Affected:
Working Resources Inc., BadBlue Enterprise Edition 2.52 and earlier
Working Resources Inc., BadBlue Personal Edition 2.52 and earlier
Microsoft Windows Any version
Recommendation Upgrade to the latest version of BadBlue (2.61 or later), available from the BadBlue Download Web site at http://www.badblue.com/down.htm
Related URL CVE-2004-1727 (CVE)
Related URL 10983 (SecurityFocus)
Related URL 17064 (ISS)