ntop HTTP Basic Authentication NULL Pointer Dereference Denial Of Service Vulnerability
BID:36074
Info
ntop HTTP Basic Authentication NULL Pointer Dereference Denial Of Service Vulnerability
| Bugtraq ID: | 36074 |
| Class: | Design Error |
| CVE: |
CVE-2009-2732 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 18 2009 12:00AM |
| Updated: | Sep 14 2010 01:23PM |
| Credit: | Brad Antoniewicz |
| Vulnerable: |
ntop ntop 3.3.10 ntop ntop 3.3.9 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 Luca Deri ntop 3.2 Luca Deri ntop 3.1 |
| Not Vulnerable: | |
Discussion
ntop HTTP Basic Authentication NULL Pointer Dereference Denial Of Service Vulnerability
The 'ntop' tool is prone to a denial-of-service vulnerability because of a NULL-pointer dereference that occurs when crafted HTTP Basic Authentication credentials are received by the embedded webserver.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users.
This issue affects ntop 3.3.10; other versions may also be affected.
The 'ntop' tool is prone to a denial-of-service vulnerability because of a NULL-pointer dereference that occurs when crafted HTTP Basic Authentication credentials are received by the embedded webserver.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users.
This issue affects ntop 3.3.10; other versions may also be affected.
Exploit / POC
ntop HTTP Basic Authentication NULL Pointer Dereference Denial Of Service Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
ntop HTTP Basic Authentication NULL Pointer Dereference Denial Of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Corporate Server 4.0
MandrakeSoft Corporate Server 4.0 x86_64
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Corporate Server 4.0
-
Mandriva ntop-3.2-10.1.20060mlcs4.i586.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 4.0 x86_64
-
Mandriva ntop-3.2-10.1.20060mlcs4.x86_64.rpm
http://www.mandriva.com/en/download/
References
ntop HTTP Basic Authentication NULL Pointer Dereference Denial Of Service Vulnerability
References:
References: