Galacticomm Worldgroup Remote Web Server Denial of Service Vulnerability
BID:4186
Info
Galacticomm Worldgroup Remote Web Server Denial of Service Vulnerability
| Bugtraq ID: | 4186 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2002-0335 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 27 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | Discovered by the Limpid Byte team <[email protected]> (http://lbyte.void.ru). |
| Vulnerable: |
Galacticomm Worldgroup LITE Personal Server 3.20 Galacticomm Worldgroup Enterprise Edition 3.20 |
| Not Vulnerable: | |
Discussion
Galacticomm Worldgroup Remote Web Server Denial of Service Vulnerability
Galacticomm Worldgroup is a community building package of both client and server software for Microsoft Windows. Worldgroup is based on BBS software, and includes web and ftp servers.
A vulnerability has been reported in the web server included with Worldgroup. If a HTTP GET request is received by the server consisting of a long string of arbitrary characters, the server will crash. A restart may be required in order to regain normal functionality.
Earlier versions of Worldgroup may share this vulnerability.
Galacticomm Worldgroup is a community building package of both client and server software for Microsoft Windows. Worldgroup is based on BBS software, and includes web and ftp servers.
A vulnerability has been reported in the web server included with Worldgroup. If a HTTP GET request is received by the server consisting of a long string of arbitrary characters, the server will crash. A restart may be required in order to regain normal functionality.
Earlier versions of Worldgroup may share this vulnerability.
Exploit / POC
Galacticomm Worldgroup Remote Web Server Denial of Service Vulnerability
An exploit has been provided by the Limpid Byte team:
An exploit has been provided by the Limpid Byte team:
Solution / Fix
Galacticomm Worldgroup Remote Web Server Denial of Service Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Galacticomm Worldgroup Remote Web Server Denial of Service Vulnerability
References:
References:
- Galacticomm Homepage (Galacticomm)
- Limpid Byte Homepage (Limpid Byte)