Multiple remote vulnerabilities reportedly affect KaZaAs Sig2Dat protocol functionality. These issues are due to a failure of the application to properly sanitize user-supplied input prior to using it in critical actions.
An attacker may leverage these issues to cause the affected application to crash, denying service to legitimate users, and to create files in arbitrary directories that are readable to the affected application.
Read the complete story @ Aviran’s Place
Related Posts
- Security Flaw Found In Trillian IM Client
- Firefox JavaScript security “a complete mess”? More like a hoax
- Google: We’ve fixed desktop search tool flaw
- ‘Highly critical’ Linux flaw patches
- IE flaw threat hits the roof
Zeropaid on Facebook

