NCSA HTTPd Buffer Overflow Vulnerability
BID:3158
Info
NCSA HTTPd Buffer Overflow Vulnerability
| Bugtraq ID: | 3158 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 17 1995 12:00AM |
| Updated: | Feb 17 1995 12:00AM |
| Credit: | The information for this vulnerability entry came from a CERT advisory. |
| Vulnerable: |
NCSA httpd 1.3 NCSA httpd 1.2 NCSA httpd 1.1 NCSA httpd 1.0 |
| Not Vulnerable: | |
Discussion
NCSA HTTPd Buffer Overflow Vulnerability
NCSA HTTPd is a free, open-source web server for *nix systems.
NCSA HTTPd versions 1.3 and earlier are prone to an exploitable buffer overflow(in the username field) which will allow malicious remote users to execute arbitrary code with the privileges of the webserver process.
Successful exploitation of this vulnerability will allow a remote attacker to gain local access to the host.
NCSA HTTPd is a free, open-source web server for *nix systems.
NCSA HTTPd versions 1.3 and earlier are prone to an exploitable buffer overflow(in the username field) which will allow malicious remote users to execute arbitrary code with the privileges of the webserver process.
Successful exploitation of this vulnerability will allow a remote attacker to gain local access to the host.
Exploit / POC
NCSA HTTPd Buffer Overflow Vulnerability
Exploits are available.
Exploits are available.