Essentia Web Server Long URL Buffer Overflow Vulnerability
BID:4159
Info
Essentia Web Server Long URL Buffer Overflow Vulnerability
| Bugtraq ID: | 4159 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0313 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 22 2002 12:00AM |
| Updated: | Feb 20 2007 09:46PM |
| Credit: | This vulnerability was submitted to BugTraq on February 22nd, 2002 by "Tamer Sahin" <[email protected]>. |
| Vulnerable: |
Essen Essentia Web Server 2.1 |
| Not Vulnerable: | |
Discussion
Essentia Web Server Long URL Buffer Overflow Vulnerability
Essentia Web Server is a multi-threaded HTTP server designed for Microsoft Windows and Linux environments. Essentia is maintained by Essen.
Essentia is prone to a remote denial of service. This condition may be triggered by submitting an excessively long URL (2000+ bytes). Successful exploitation will deny service to legitimate users and will require that the webserver be restarted to regain normal functionality.
This problem is due to a lack of bounds-checking on the length of URLs. Because of this, an attacker may also be able to exploit this condition to execute arbitrary code.
This issue was reported for Essentia Web Sever v2.1; earlier versions may also be affected.
Essentia Web Server is a multi-threaded HTTP server designed for Microsoft Windows and Linux environments. Essentia is maintained by Essen.
Essentia is prone to a remote denial of service. This condition may be triggered by submitting an excessively long URL (2000+ bytes). Successful exploitation will deny service to legitimate users and will require that the webserver be restarted to regain normal functionality.
This problem is due to a lack of bounds-checking on the length of URLs. Because of this, an attacker may also be able to exploit this condition to execute arbitrary code.
This issue was reported for Essentia Web Sever v2.1; earlier versions may also be affected.
Exploit / POC
Essentia Web Server Long URL Buffer Overflow Vulnerability
An exploit has been made available by B-r00t:
An exploit has been made available by B-r00t: