eEye Digital Security SecureIIS Overflow Protection Bypass Vulnerability
BID:2744
Info
eEye Digital Security SecureIIS Overflow Protection Bypass Vulnerability
| Bugtraq ID: | 2744 |
| Class: | Design Error |
| CVE: |
CVE-2001-0523 |
| Remote: | Yes |
| Local: | No |
| Published: | May 18 2001 12:00AM |
| Updated: | Jul 11 2009 06:06AM |
| Credit: | Discovered and posted to Bugtraq by Alliance Security Labs <[email protected]> on May 18, 2001. |
| Vulnerable: |
Eeye SecureIIS 1.0.3 Eeye SecureIIS 1.0.2 |
| Not Vulnerable: |
Eeye SecureIIS 1.0.4 |
Discussion
eEye Digital Security SecureIIS Overflow Protection Bypass Vulnerability
SecureIIS offers the ability to detect and block requests that have oversized fields in their HTTP headers. These requests may be indicative of an attempt to exploit a buffer overflow vulnerability in an application that uses header data.
It has been reported that SecureIIS does not adequately block some of these requests containing oversized HTTP fields.
Attackers may be able to use this vulnerability to exploit buffer overflow attacks in vulnerable applications on hosts protected by SecureIIS.
SecureIIS offers the ability to detect and block requests that have oversized fields in their HTTP headers. These requests may be indicative of an attempt to exploit a buffer overflow vulnerability in an application that uses header data.
It has been reported that SecureIIS does not adequately block some of these requests containing oversized HTTP fields.
Attackers may be able to use this vulnerability to exploit buffer overflow attacks in vulnerable applications on hosts protected by SecureIIS.
References
eEye Digital Security SecureIIS Overflow Protection Bypass Vulnerability
References:
References:
- SecureIIS Product Homepage (eEye Digital Security)