CVE-2008-1337

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
14/03/2008
Last modified:
09/04/2025

Description

The instant message service in Timbuktu Pro 8.6.5 RC 229 and earlier for Windows allows remote attackers to cause (1) a denial of service (daemon crash) via an invalid Version field or (2) a denial of service (CPU consumption and daemon termination) via an invalid or partial message.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:netopia:timbuktu_pro:8.6.5:rc_229:*:*:*:*:*:*