CVE-2009-3591
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 53%
from disclosure to weapon0 days
Published on NVDOct 8
1st PoCOct 6
metasploitOct 5
exploitation probability
53%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Dopewars 1.5.12 allows remote attackers to cause a denial of service (segmentation fault) via a REQUESTJET message with an invalid location.
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/33269unverifiedexploitdbwww.exploit-db.com/exploits/10004unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://dopewars.svn.sourceforge.net/viewvc/dopewars/dopewars/trunk/ChangeLog?view=markup&pathrev=1033http://dopewars.svn.sourceforge.net/viewvc/dopewars/dopewars/trunk/src/serverside.c?r1=1023&r2=1033&pathrev=1033http://secunia.com/advisories/36961http://www.securityfocus.com/archive/1/507012/100/0/threadedhttp://www.securityfocus.com/bid/36606