giFT-FastTrack HTTP Header Parser Remote Denial Of Service Vulnerability
BID:10604
Info
giFT-FastTrack HTTP Header Parser Remote Denial Of Service Vulnerability
| Bugtraq ID: | 10604 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2004-0604 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 24 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | Alan F. disclosed this vulnerability to the vendor. |
| Vulnerable: |
giFT-FastTrack giFT-FastTrack 0.8.6 giFT-FastTrack giFT-FastTrack 0.8.5 giFT-FastTrack giFT-FastTrack 0.8.4 giFT-FastTrack giFT-FastTrack 0.8.3 giFT-FastTrack giFT-FastTrack 0.8.2 giFT-FastTrack giFT-FastTrack 0.8.1 giFT-FastTrack giFT-FastTrack 0.8 .0 Gentoo Linux 1.4 |
| Not Vulnerable: |
giFT-FastTrack giFT-FastTrack 0.8.7 |
Discussion
giFT-FastTrack HTTP Header Parser Remote Denial Of Service Vulnerability
It is reported that the giFT-FastTrack module is prone to a denial of service vulnerability in its HTTP header parser.
A remote attacker who sends malformed HTTP requests to an affected giFT server can crash the server.
The vendor has released version 0.8.7, addressing this issue. All prior versions are reported affected by this vulnerability.
It is reported that the giFT-FastTrack module is prone to a denial of service vulnerability in its HTTP header parser.
A remote attacker who sends malformed HTTP requests to an affected giFT server can crash the server.
The vendor has released version 0.8.7, addressing this issue. All prior versions are reported affected by this vulnerability.
Exploit / POC
giFT-FastTrack HTTP Header Parser Remote Denial Of Service Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
giFT-FastTrack HTTP Header Parser Remote Denial Of Service Vulnerability
Solution:
The vendor has released version 0.8.7 addressing this issue.
Gentoo Linux has released advisory GLSA 200406-19 dealing with this issue. Please see the referenced advisory for further information. Users of affected packages are urged to execute the following as superuser:
emerge sync
emerge -pv ">=net-p2p/gift-fasttrack-0.8.7"
emerge ">=net-p2p/gift-fasttrack-0.8.7"
giFT-FastTrack giFT-FastTrack 0.8 .0
giFT-FastTrack giFT-FastTrack 0.8.1
giFT-FastTrack giFT-FastTrack 0.8.2
giFT-FastTrack giFT-FastTrack 0.8.3
giFT-FastTrack giFT-FastTrack 0.8.4
giFT-FastTrack giFT-FastTrack 0.8.5
giFT-FastTrack giFT-FastTrack 0.8.6
Solution:
The vendor has released version 0.8.7 addressing this issue.
Gentoo Linux has released advisory GLSA 200406-19 dealing with this issue. Please see the referenced advisory for further information. Users of affected packages are urged to execute the following as superuser:
emerge sync
emerge -pv ">=net-p2p/gift-fasttrack-0.8.7"
emerge ">=net-p2p/gift-fasttrack-0.8.7"
giFT-FastTrack giFT-FastTrack 0.8 .0
-
giFT-FastTrack giFT-FastTrack-0.8.7.tar.gz
http://download.berlios.de/gift-fasttrack/giFT-FastTrack-0.8.7.tar.gz
giFT-FastTrack giFT-FastTrack 0.8.1
-
giFT-FastTrack giFT-FastTrack-0.8.7.tar.gz
http://download.berlios.de/gift-fasttrack/giFT-FastTrack-0.8.7.tar.gz
giFT-FastTrack giFT-FastTrack 0.8.2
-
giFT-FastTrack giFT-FastTrack-0.8.7.tar.gz
http://download.berlios.de/gift-fasttrack/giFT-FastTrack-0.8.7.tar.gz
giFT-FastTrack giFT-FastTrack 0.8.3
-
giFT-FastTrack giFT-FastTrack-0.8.7.tar.gz
http://download.berlios.de/gift-fasttrack/giFT-FastTrack-0.8.7.tar.gz
giFT-FastTrack giFT-FastTrack 0.8.4
-
giFT-FastTrack giFT-FastTrack-0.8.7.tar.gz
http://download.berlios.de/gift-fasttrack/giFT-FastTrack-0.8.7.tar.gz
giFT-FastTrack giFT-FastTrack 0.8.5
-
giFT-FastTrack giFT-FastTrack-0.8.7.tar.gz
http://download.berlios.de/gift-fasttrack/giFT-FastTrack-0.8.7.tar.gz
giFT-FastTrack giFT-FastTrack 0.8.6
-
giFT-FastTrack giFT-FastTrack-0.8.7.tar.gz
http://download.berlios.de/gift-fasttrack/giFT-FastTrack-0.8.7.tar.gz
References
giFT-FastTrack HTTP Header Parser Remote Denial Of Service Vulnerability
References:
References:
- giFT Home Page (giFT)
- giFT-FastTrack Home Page (giFT-FastTrack)