[DCA-0009 - NetWordDLS Finger Server Denial of Service] [Software] - NetWordDLS Finger Server [Vendor Product Description] - A windows server application that reports back to users the machine name and the current logged on user [Bug Description] - Server does not validate the input size leading to a Denial Of Service flaw while sending more than 4095 characters to it. [History] - Advisory sent to vendor on 06/20/2010. - No vendor response - Advisory publised on 08/01/2010 [Impact] - Low [Affected Version] - Finger Server 1.0 - Prior versions may also be vulnerable [Vendor Reply] [Codes] ---------------------------------------------------------------------------------------- [Credits] Ewerson Guimaraes (Crash) Pentester/Researcher DcLabs Security Team www.dclabs.com.br [Greetz] ipax and all DcLabs members.