Unrated severityNVD Advisory· Published Aug 14, 2008· Updated Apr 23, 2026
CVE-2008-3680
CVE-2008-3680
Description
The decryption function in Flagship Industries Ventrilo 3.0.2 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) by sending a type 0 packet with an invalid version followed by another packet to TCP port 3784.
Affected products
18cpe:2.3:a:flagship_industries:ventrilo:1:*:*:*:*:*:*:*+ 17 more
- cpe:2.3:a:flagship_industries:ventrilo:1:*:*:*:*:*:*:*
- cpe:2.3:a:flagship_industries:ventrilo:1.01:*:*:*:*:*:*:*
- cpe:2.3:a:flagship_industries:ventrilo:1.03:*:*:*:*:*:*:*
- cpe:2.3:a:flagship_industries:ventrilo:1.04:*:*:*:*:*:*:*
- cpe:2.3:a:flagship_industries:ventrilo:1.05:*:*:*:*:*:*:*
- cpe:2.3:a:flagship_industries:ventrilo:1.06:*:*:*:*:*:*:*
- cpe:2.3:a:flagship_industries:ventrilo:2:*:*:*:*:*:*:*
- cpe:2.3:a:flagship_industries:ventrilo:2.1:*:*:*:*:*:*:*
- cpe:2.3:a:flagship_industries:ventrilo:2.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:flagship_industries:ventrilo:2.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:flagship_industries:ventrilo:2.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:flagship_industries:ventrilo:2.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:flagship_industries:ventrilo:2.2:*:*:*:*:*:*:*
- cpe:2.3:a:flagship_industries:ventrilo:2.3:*:*:*:*:*:*:*
- cpe:2.3:a:flagship_industries:ventrilo:2.3.2:prototype.6:*:*:*:*:*:*
- cpe:2.3:a:flagship_industries:ventrilo:2.3.2:prototype.9:*:*:*:*:*:*
- cpe:2.3:a:flagship_industries:ventrilo:3:*:*:*:*:*:*:*
- cpe:2.3:a:flagship_industries:ventrilo:3.0.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- aluigi.org/poc/ventrilobotomy.zipnvdExploit
- www.securityfocus.com/bid/30675nvdExploit
- secunia.com/advisories/31466nvdVendor Advisory
- aluigi.altervista.org/adv/ventrilobotomy-adv.txtnvd
- secunia.com/advisories/34696nvd
- security.gentoo.org/glsa/glsa-200904-13.xmlnvd
- securityreason.com/securityalert/4156nvd
- www.securityfocus.com/archive/1/495448/100/0/threadednvd
- www.vupen.com/english/advisories/2008/2365nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/44428nvd
- www.exploit-db.com/exploits/6237nvd
News mentions
0No linked articles in our index yet.