FlatFrag 0.3 and earlier allows remote attackers to cause a denial of service (crash) by sending an NT_CONN_OK command from a client that is not connected, which triggers a null dereference.Referenceshttp://aluigi.altervista.org/adv/flatfragz-adv.txthttp://www.vupen.com/english/advisories/2005/2285http://www.securityfocus.com/bid/15287http://www.osvdb.org/20770http://www.securityfocus.com/archive/1/415636/30/0/threadedhttp://marc.info/?l=full-disclosure&m=113096078606274&w=2