Perforce P4Web Content-Length Header Remote Denial Of Service Vulnerability
BID:26806
Info
Perforce P4Web Content-Length Header Remote Denial Of Service Vulnerability
| Bugtraq ID: | 26806 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2007-6349 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2007 12:00AM |
| Updated: | Mar 13 2008 03:41AM |
| Credit: | Oliver Karow of Symantec Vulnerability Research discovered this issue. |
| Vulnerable: |
Perforce P4Web 2006.2 Perforce P4Web 2006.1 |
| Not Vulnerable: |
Perforce P4Web 2007.2 |
Discussion
Perforce P4Web Content-Length Header Remote Denial Of Service Vulnerability
Perforce P4Web is prone to a remote denial-of-service vulnerability because it fails to handle specially crafted HTTP requests.
An attacker can exploit this issue to cause the application to consume excessive CPU and memory resources. Successful attacks will deny service to legitimate users.
P4Web 2006.2 and prior versions running on Windows are affected.
Perforce P4Web is prone to a remote denial-of-service vulnerability because it fails to handle specially crafted HTTP requests.
An attacker can exploit this issue to cause the application to consume excessive CPU and memory resources. Successful attacks will deny service to legitimate users.
P4Web 2006.2 and prior versions running on Windows are affected.
Exploit / POC
Perforce P4Web Content-Length Header Remote Denial Of Service Vulnerability
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
Perforce P4Web Content-Length Header Remote Denial Of Service Vulnerability
Solution:
The vendor released P4Web 2007.2 to address this issue. Please see the references for more information.
Perforce P4Web 2006.2
Perforce P4Web 2006.1
Solution:
The vendor released P4Web 2007.2 to address this issue. Please see the references for more information.
Perforce P4Web 2006.2
-
Perforce Software r07.2/bin.ntx86/p4webinst.exe
ftp://ftp.perforce.com/perforce/r07.2/bin.ntx86/p4webinst.exe
Perforce P4Web 2006.1
-
Perforce Software r07.2/bin.ntx86/p4webinst.exe
ftp://ftp.perforce.com/perforce/r07.2/bin.ntx86/p4webinst.exe
References
Perforce P4Web Content-Length Header Remote Denial Of Service Vulnerability
References:
References:
- P4Web Release Notes 2007.2 - October 17, 2007 (Perforce Software)
- Vendor Homepage (Perforce Software)
- SYMSA-2007-015 ([email protected])