Description
VirtualTablet Server 3.0.2 contains a denial of service vulnerability that allows attackers to crash the service by sending oversized string payloads through the Thrift protocol. Attackers can exploit the vulnerability by sending a long string to the send_say() method, causing the server to become unresponsive.
Problem types
Allocation of Resources Without Limits or Throttling
Product status
Credits
Dolev Farhi
References
www.exploit-db.com/exploits/48402 (ExploitDB-48402)
www.sunnysidesoft.com/ (Official Product Homepage)
www.vulncheck.com/...tualtablet-server-denial-of-service-poc (VulnCheck Advisory: VirtualTablet Server 3.0.2 - Denial of Service (PoC))