Phusion Webserver Long URL Buffer Overflow Vulnerability
BID:4119
Info
Phusion Webserver Long URL Buffer Overflow Vulnerability
| Bugtraq ID: | 4119 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0289 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 16 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | This issue was submitted to BugTraq on February 16th, 2002 by Alex Hernandez <[email protected]>. |
| Vulnerable: |
BBShareware.Com Phusion Webserver 1.0 |
| Not Vulnerable: | |
Discussion
Phusion Webserver Long URL Buffer Overflow Vulnerability
Phusion Webserver is a commercial HTTP server that runs on Microsoft Windows 9x/NT/2000 operating systems.
Phusion Webserver does not perform sufficient bounds checking of externally supplied data. As a result, it is possible for a remote attacker to submit an excessively long web request which may cause stack variables to be overwritten with attacker-supplied instructions.
As webservers normally run with SYSTEM privileges on Microsoft Windows operating systems, this may result in a full compromise of a host running the vulnerable software.
It should be noted that this unchecked buffer may also be exploited to cause a denial of service condition.
Phusion Webserver is a commercial HTTP server that runs on Microsoft Windows 9x/NT/2000 operating systems.
Phusion Webserver does not perform sufficient bounds checking of externally supplied data. As a result, it is possible for a remote attacker to submit an excessively long web request which may cause stack variables to be overwritten with attacker-supplied instructions.
As webservers normally run with SYSTEM privileges on Microsoft Windows operating systems, this may result in a full compromise of a host running the vulnerable software.
It should be noted that this unchecked buffer may also be exploited to cause a denial of service condition.
Exploit / POC
Phusion Webserver Long URL Buffer Overflow Vulnerability
The following proof-of-concept was provided by Alex Hernandez <[email protected]>:
The following proof-of-concept was provided by Alex Hernandez <[email protected]>: