Anti-Web HTTPD Script Engine Heap Overflow Vulnerability
BID:3814
Info
Anti-Web HTTPD Script Engine Heap Overflow Vulnerability
| Bugtraq ID: | 3814 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 07 2002 12:00AM |
| Updated: | Jan 07 2002 12:00AM |
| Credit: | This vulnerability was discovered by 3APA3A <[email protected]>, and announced via Bugtraq on January 6, 2002. |
| Vulnerable: |
Hardcore Software Anti-Web HTTPD 2.2 |
| Not Vulnerable: |
Hardcore Software Anti-Web HTTPD 2.2.1 |
Discussion
Anti-Web HTTPD Script Engine Heap Overflow Vulnerability
Anti-Web HTTPD is a freely available, open source web server designed for use on the Linux platform. It is maintained by Doug Hoyte.
Under some circumstances, it may be possible to take advantage of a heap overflow in awhttpd.
awhttpd does not properly handle the loading of script code. As a result, a local user with access to load scripts could take advantage of this problem to execute arbitrary code. This could result in the user gaining the same privilege as the HTTPD process (by default, UID/GID 32767)..
Anti-Web HTTPD is a freely available, open source web server designed for use on the Linux platform. It is maintained by Doug Hoyte.
Under some circumstances, it may be possible to take advantage of a heap overflow in awhttpd.
awhttpd does not properly handle the loading of script code. As a result, a local user with access to load scripts could take advantage of this problem to execute arbitrary code. This could result in the user gaining the same privilege as the HTTPD process (by default, UID/GID 32767)..
Exploit / POC
Anti-Web HTTPD Script Engine Heap Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Anti-Web HTTPD Script Engine Heap Overflow Vulnerability
Solution:
Vendor supplied fix available:
Hardcore Software Anti-Web HTTPD 2.2
Solution:
Vendor supplied fix available:
Hardcore Software Anti-Web HTTPD 2.2
-
Hardcore Software awhttpd-2.2.1.tgz
http://hardcoresoftware.cjb.net/awhttpd/awhttpd-2.2.1.tgz
References
Anti-Web HTTPD Script Engine Heap Overflow Vulnerability
References:
References: