AnalogX SimpleServer WWW 1.05 DoS Vulnerability
BID:1349
Info
AnalogX SimpleServer WWW 1.05 DoS Vulnerability
| Bugtraq ID: | 1349 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2000-0473 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jun 15 2000 12:00AM |
| Updated: | Jul 11 2009 02:56AM |
| Credit: | Discovered by and posted to Bugtraq on June 15, 2000 by Ussr Labs <[email protected]>. |
| Vulnerable: |
AnalogX SimpleServer:WWW 1.0.5 |
| Not Vulnerable: | |
Discussion
AnalogX SimpleServer WWW 1.05 DoS Vulnerability
If a long url is sent to port 80 on a SimpleServer WWW 1.05 it could cause the service to stop responding. A restart of the server service is required inorder to regain normal functionality.
If a long url is sent to port 80 on a SimpleServer WWW 1.05 it could cause the service to stop responding. A restart of the server service is required inorder to regain normal functionality.
Exploit / POC
AnalogX SimpleServer WWW 1.05 DoS Vulnerability
http://target/cgi-bin/long_string_here
http://target/cgi-bin/long_string_here
Solution / Fix
AnalogX SimpleServer WWW 1.05 DoS Vulnerability
Solution:
Solution:
AnalogX has released the following upgrade which addresses this issue:
AnalogX SimpleServer:WWW 1.0.5
Solution:
Solution:
AnalogX has released the following upgrade which addresses this issue:
AnalogX SimpleServer:WWW 1.0.5
-
AnalogX sswwwi
http://www.analogx.com/files/sswwwi.exe