Multiple IEA Software Products HTTP POST Request Denial of Service Vulnerability
BID:27701
Info
Multiple IEA Software Products HTTP POST Request Denial of Service Vulnerability
| Bugtraq ID: | 27701 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-5284 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 08 2008 12:00AM |
| Updated: | Dec 01 2008 11:52PM |
| Credit: | Luigi Auriemma is credited with discovering this issue. |
| Vulnerable: |
IEA Software RadiusX 5.1.38 IEA Software RadiusNT 5.1.38 IEA Software Radius test client 4.0.20 IEA Software Emerald 5.0.49 IEA Software Air Marshal 2.0.4 |
| Not Vulnerable: | |
Discussion
Multiple IEA Software Products HTTP POST Request Denial of Service Vulnerability
Multiple IEA Software products are prone to a denial-of-service vulnerability.
Successfully exploiting this issue will allow attackers to crash the affected application, denying service to legitimate users.
This issue affects the following applications:
- Emerald 5.0.49 and prior versions
- RadiusNT and RadiusX 5.1.38 and prior versions
- Radius test client 4.0.20 and prior versions
- Air Marshal 2.0.4 and prior versions
Multiple IEA Software products are prone to a denial-of-service vulnerability.
Successfully exploiting this issue will allow attackers to crash the affected application, denying service to legitimate users.
This issue affects the following applications:
- Emerald 5.0.49 and prior versions
- RadiusNT and RadiusX 5.1.38 and prior versions
- Radius test client 4.0.20 and prior versions
- Air Marshal 2.0.4 and prior versions
Exploit / POC
Multiple IEA Software Products HTTP POST Request Denial of Service Vulnerability
The following proof-of-concept exploit code is available:
POST / HTTP/1.0
Host: localhost
Content-Length: 2147483647
The following proof-of-concept exploit code is available:
POST / HTTP/1.0
Host: localhost
Content-Length: 2147483647
Solution / Fix
Multiple IEA Software Products HTTP POST Request Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Multiple IEA Software Products HTTP POST Request Denial of Service Vulnerability
References:
References:
- IEA Software Homepage (IEA Software)
- NULL byte writing in Emerald, RadiusNT/X and Air Marshal (Luigi Auriemma
)