MySQL MaxDB WAHTTP Server Remote Denial Of Service Vulnerability
BID:11843
Info
MySQL MaxDB WAHTTP Server Remote Denial Of Service Vulnerability
| Bugtraq ID: | 11843 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 07 2004 12:00AM |
| Updated: | Dec 07 2004 12:00AM |
| Credit: | This issue was discovered by Evgeny Demidov <[email protected]>. |
| Vulnerable: |
MySQL AB MaxDB 7.5 .00.18 MySQL AB MaxDB 7.5 .00.16 MySQL AB MaxDB 7.5 .00.15 MySQL AB MaxDB 7.5 .00.14 MySQL AB MaxDB 7.5 .00.12 MySQL AB MaxDB 7.5 .00.11 MySQL AB MaxDB 7.5 .00.08 |
| Not Vulnerable: | |
Discussion
MySQL MaxDB WAHTTP Server Remote Denial Of Service Vulnerability
A remote denial of service vulnerability has been reported to affect the MySQL MaxDB WAHTTP server. This issue is due to a failure of the server to handle malformed requests.
An attacker may leverage this issue to cause the affected Web server to crash, denying service to legitimate users.
A remote denial of service vulnerability has been reported to affect the MySQL MaxDB WAHTTP server. This issue is due to a failure of the server to handle malformed requests.
An attacker may leverage this issue to cause the affected Web server to crash, denying service to legitimate users.
Exploit / POC
MySQL MaxDB WAHTTP Server Remote Denial Of Service Vulnerability
No exploit is required to leverage this issue. The following proof of concept exploit has been provided:
To reproduce it, execute the following command:
$ telnet localhost 9999
GET /file/not/found HTTP/1.0
[ENTER]
[ENTER]
No exploit is required to leverage this issue. The following proof of concept exploit has been provided:
To reproduce it, execute the following command:
$ telnet localhost 9999
GET /file/not/found HTTP/1.0
[ENTER]
[ENTER]
Solution / Fix
MySQL MaxDB WAHTTP Server Remote Denial Of Service Vulnerability
Solution:
It has been reported that MaxDB 7.5.00.19 has been released to resolve this issue, although this is not confirmed. Users are advised to contact the vendor for more information on obtaining possible upgrades.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It has been reported that MaxDB 7.5.00.19 has been released to resolve this issue, although this is not confirmed. Users are advised to contact the vendor for more information on obtaining possible upgrades.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
MySQL MaxDB WAHTTP Server Remote Denial Of Service Vulnerability
References:
References:
- MaxDB Homepage (MySQL AB)
- MaxDB WebTools <= 7.5.00.18 buffer overflow and Denial of Service (Evgeny Demidov
)