Ventrilo: Denial of service A vulnerability has been discovered in Ventrilo, allowing for a Denial of Service. ventrilo-server-bin 2009-04-14 2009-04-14 234819 remote 3.0.3 3.0.3

Ventrilo is a Voice over IP group communication server.

Luigi Auriemma reported a NULL pointer dereference in Ventrilo when processing packets with an invalid version number followed by another packet.

A remote attacker could send specially crafted packets to the server, resulting in a crash.

There is no known workaround at this time.

All Ventrilo users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=media-sound/ventrilo-server-bin-3.0.3"
CVE-2008-3680 p-y p-y