CVE-2007-1327: Null Pointer Dereference
Published Mar 7, 2007
·Updated
The SILCSERVERCMDFUNC function in apps/silcd/command.c in silc-server 1.0.2 allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a request without a cipher algorithm and an invalid HMAC algorithm.
Affected Software
1 affected component
silc silc-server=1.0.2
Event History
Mar 7, 2007
CVE Published
09:19 PM
Mar 8, 2007
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1327?
CVE-2007-1327 has a medium severity rating as it allows for a denial of service through a daemon crash.
2
How do I fix CVE-2007-1327?
To fix CVE-2007-1327, upgrade to a version of silc-server that is higher than 1.0.2.
3
What is affected by CVE-2007-1327?
CVE-2007-1327 affects the silc-server version 1.0.2.
4
What happens if CVE-2007-1327 is exploited?
Exploiting CVE-2007-1327 can lead to a denial of service due to a NULL pointer dereference causing the server to crash.
5
Who are the attackers that could exploit CVE-2007-1327?
Remote attackers can exploit CVE-2007-1327 by sending requests without a cipher algorithm and an invalid HMAC algorithm.