Description
jetCast Server 2.0 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Log directory configuration field. Attackers can paste a buffer of 5000 characters into the Log directory input, then click Start to trigger a crash that terminates the server process.
Problem types
Improper Validation of Specified Index, Position, or Offset in Input
Product status
Credits
Victor Mondragón
References
www.exploit-db.com/exploits/46819 (ExploitDB-46819)
www.jetaudio.com/ (Official Product Homepage)
www.jetaudio.com/...Audio/Download/jetCast/build/JCS2000.exe (Product Reference)
www.vulncheck.com/...ver-denial-of-service-via-log-directory (VulnCheck Advisory: jetCast Server 2.0 Denial of Service via Log Directory)