Symantec PCAnywhere32 8.0 - Denial of Service



EKU-ID: 24843 CVE: CVE-1999-1028;OSVDB-4720 OSVDB-ID:
Author: Chris Radigan Published: 1999-05-11 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/288/info

Servers running PCAnywhere32 with TCP/IP networking are subject to a Denial of Service attack that will hang the server at 100% CPU utilization. A malicious user may initiate this DoS by connecting to tcp port 5631 on the PCAnywhere server input a large amount of data when prompted with "Please press <Enter>".

Connect to tcp 5631. At the Please press <Enter> prompt, transfer a large amount of data to the PCAnywhere server. This will peg the CPU utilization at 100%.