Xitami Webserver MS-DOS Device Name DoS Vulnerability
BID:2622
Info
Xitami Webserver MS-DOS Device Name DoS Vulnerability
| Bugtraq ID: | 2622 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2001-0391 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 17 2001 12:00AM |
| Updated: | Jul 11 2009 06:06AM |
| Credit: | Reported to bugtraq by nemesystm <[email protected]> |
| Vulnerable: |
Imatix Xitami for Windows 2.5 b4 Imatix Xitami for Windows 2.4 d7 |
| Not Vulnerable: |
Imatix Xitami for Windows 2.5 b5 Imatix Xitami for Windows 2.4 d9 |
Exploit / POC
Xitami Webserver MS-DOS Device Name DoS Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Xitami Webserver MS-DOS Device Name DoS Vulnerability
Solution:
In a followup advisory dated April 18, 2001, the vendor notes:
---
we plan to release a minor update to both Xitami 2.4 (release code), and Xitami 2.5 (beta test code)
with a work around for this issue, possibly including a hard coded check for AUX that is always done, in addition to the Win32 QueryDosDevice() where available. This update will be announced on the Xitami user mailing list, and announcement list when it is available.
Meanwhile some Xitami users have reported that defining an Xitami alias for "AUX" that points at some non-existant file avoids the issue reported (as the alias expansion is done before any files are opened); we would suggest those looking for an immediate work around consider this.
---
Imatix Xitami for Windows 2.4 d7
Imatix Xitami for Windows 2.5 b4
Solution:
In a followup advisory dated April 18, 2001, the vendor notes:
---
we plan to release a minor update to both Xitami 2.4 (release code), and Xitami 2.5 (beta test code)
with a work around for this issue, possibly including a hard coded check for AUX that is always done, in addition to the Win32 QueryDosDevice() where available. This update will be announced on the Xitami user mailing list, and announcement list when it is available.
Meanwhile some Xitami users have reported that defining an Xitami alias for "AUX" that points at some non-existant file avoids the issue reported (as the alias expansion is done before any files are opened); we would suggest those looking for an immediate work around consider this.
---
Imatix Xitami for Windows 2.4 d7
-
Imatix Xitami for Windows 2.4d9
http://www.xitami.com/download.htm
Imatix Xitami for Windows 2.5 b4
-
Imatix Xitami for Windows 2.5b5
http://www.xitami.com/download.htm