NetWin WebNEWS Remote Buffer Overflow Vulnerability
BID:4124
Info
NetWin WebNEWS Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 4124 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 18 2002 12:00AM |
| Updated: | Feb 18 2002 12:00AM |
| Credit: | Published by Mark Litchfield ([email protected]). |
| Vulnerable: |
NetWin WebNEWS 1.1 j NetWin WebNEWS 1.1 i NetWin WebNEWS 1.1 h |
| Not Vulnerable: |
NetWin WebNEWS 1.1 k |
Discussion
NetWin WebNEWS Remote Buffer Overflow Vulnerability
WebNEWS is a server product designed to provide access to news groups through a web interface. It is able to connect to any standard NNTP server, and is available for Windows, BSD, Linux and most Unix systems.
A vulnerability has been reported in some versions of WebNEWS. It has been reported that supplying a value longer than approximately 1500 characters as the group parameter may cause a buffer overflow, overwriting stack memory. Exploitation of this vulnerability may result in the execution of arbitrary code as the web server.
WebNEWS is a server product designed to provide access to news groups through a web interface. It is able to connect to any standard NNTP server, and is available for Windows, BSD, Linux and most Unix systems.
A vulnerability has been reported in some versions of WebNEWS. It has been reported that supplying a value longer than approximately 1500 characters as the group parameter may cause a buffer overflow, overwriting stack memory. Exploitation of this vulnerability may result in the execution of arbitrary code as the web server.
Exploit / POC
NetWin WebNEWS Remote Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.