A memory corruption flaw exists in Ezhometech EzServer. The issue is triggered when memcpy() function fails to sanitize user-supplied input during the parsing of a specially crafted AMF request, which will result in memory corruption. This may allow a remote attacker to cause a denial of service.
Classification
Location:
Remote / Network Access
Attack Type:
Denial of Service,
Input Manipulation
Impact:
Loss of Availability
Solution:
Solution Unknown
Exploit:
Exploit Public
Disclosure:
No Vendor Response
Solution
OSVDB is not aware of a confirmed solution for this vulnerability. It is possible, though not confirmed, that 7.1 may potentially address this vulnerability.