Vulnerability Description
The TeamSpeak client before 3.3.2 allows remote servers to trigger a crash via the 0xe2 0x81 0xa8 0xe2 0x81 0xa7 byte sequence, aka Unicode characters U+2068 (FIRST STRONG ISOLATE) and U+2067 (RIGHT-TO-LEFT ISOLATE).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Teamspeak | Teamspeak | < 3.3.2 |
References
- https://forum.teamspeak.com/threads/141134-Release-TeamSpeak-Client-3-3-2Release NotesVendor Advisory
- https://r4p3.net/threads/teamkilled-new-teamspeak-crash.8144/ExploitThird Party Advisory
- https://www.youtube.com/watch?v=PlVbPIs75D4ExploitThird Party Advisory
- https://forum.teamspeak.com/threads/141134-Release-TeamSpeak-Client-3-3-2Release NotesVendor Advisory
- https://r4p3.net/threads/teamkilled-new-teamspeak-crash.8144/ExploitThird Party Advisory
- https://www.youtube.com/watch?v=PlVbPIs75D4ExploitThird Party Advisory
FAQ
What is CVE-2019-15502?
CVE-2019-15502 is a vulnerability with a CVSS score of 7.5 (HIGH). The TeamSpeak client before 3.3.2 allows remote servers to trigger a crash via the 0xe2 0x81 0xa8 0xe2 0x81 0xa7 byte sequence, aka Unicode characters U+2068 (FIRST STRONG ISOLATE) and U+2067 (RIGHT-T...
How severe is CVE-2019-15502?
CVE-2019-15502 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-15502?
Check the references section above for vendor advisories and patch information. Affected products include: Teamspeak Teamspeak.