vWebServer MS DOS Device Name Denial of Service Vulnerability
BID:2978
Info
vWebServer MS DOS Device Name Denial of Service Vulnerability
| Bugtraq ID: | 2978 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-1249 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 29 2001 12:00AM |
| Updated: | Jul 11 2009 06:56AM |
| Credit: | Reported to bugtraq by Extirpater <[email protected]> on June 29, 2001. |
| Vulnerable: |
vWebServer vWebServer 1.2 |
| Not Vulnerable: | |
Discussion
vWebServer MS DOS Device Name Denial of Service Vulnerability
A problem with the webserver makes it possible to deny service to legitmate users.
By submitting a request to the webserver including the 'AUX' MS-DOS device name, the webserver can be made to cease functioning.
The process has to be manually restarted to resume normal operation.
A problem with the webserver makes it possible to deny service to legitmate users.
By submitting a request to the webserver including the 'AUX' MS-DOS device name, the webserver can be made to cease functioning.
The process has to be manually restarted to resume normal operation.
Exploit / POC
vWebServer MS DOS Device Name Denial of Service Vulnerability
See discussion.
See discussion.
References
vWebServer MS DOS Device Name Denial of Service Vulnerability
References:
References: