OFFSystem HTTP Headers Remote Buffer Overflow Vulnerability
BID:29809
Info
OFFSystem HTTP Headers Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 29809 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2851 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2008 12:00AM |
| Updated: | May 07 2015 05:28PM |
| Credit: | Vendor. |
| Vulnerable: |
OFFSystem OFFSystem 0.9.14 |
| Not Vulnerable: | |
Discussion
OFFSystem HTTP Headers Remote Buffer Overflow Vulnerability
OFFSystem is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data. The vulnerability occurs when parsing HTTP headers.
An attacker may exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts may result in a denial-of-service condition.
OFFSystem 0.19.14 and prior versions are vulnerable.
OFFSystem is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data. The vulnerability occurs when parsing HTTP headers.
An attacker may exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts may result in a denial-of-service condition.
OFFSystem 0.19.14 and prior versions are vulnerable.
Exploit / POC
OFFSystem HTTP Headers Remote Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
OFFSystem HTTP Headers Remote Buffer Overflow Vulnerability
Solution:
A fix is available. Please see the references for more information.
Solution:
A fix is available. Please see the references for more information.
References
OFFSystem HTTP Headers Remote Buffer Overflow Vulnerability
References:
References:
- OFFSystem Homepage (OFFSystem)