Sun Cobalt RaQ Service.CGI HTTP Server Denial of Service Vulnerablity
BID:4209
Info
Sun Cobalt RaQ Service.CGI HTTP Server Denial of Service Vulnerablity
| Bugtraq ID: | 4209 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0348 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 28 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | This vulnerability discovery credited to Alex Hernandez <[email protected]>. |
| Vulnerable: |
Cobalt RaQ 4.0 Cobalt RaQ 3.0 Cobalt RaQ 2.0 |
| Not Vulnerable: | |
Discussion
Sun Cobalt RaQ Service.CGI HTTP Server Denial of Service Vulnerablity
RaQ is a server appliance originally developed by Cobalt. It is now distributed and maintained by Sun Microsystems.
Under some circumstances, the HTTP server of a Cobalt RaQ system may crash. When a remote user places an excessively long request to the service.cgi script, the results can be unpredictable. It has been reported that a request such as http://www.example.com:81/cgi-bin/.cobalt/alert/service.cgi?service=/AAAAAAAAA...(Ax100000)...AAA will cause the HTTP server to crash.
RaQ is a server appliance originally developed by Cobalt. It is now distributed and maintained by Sun Microsystems.
Under some circumstances, the HTTP server of a Cobalt RaQ system may crash. When a remote user places an excessively long request to the service.cgi script, the results can be unpredictable. It has been reported that a request such as http://www.example.com:81/cgi-bin/.cobalt/alert/service.cgi?service=/AAAAAAAAA...(Ax100000)...AAA will cause the HTTP server to crash.
Exploit / POC
Sun Cobalt RaQ Service.CGI HTTP Server Denial of Service Vulnerablity
This vulnerablity may be exploit with a web browser.
This vulnerablity may be exploit with a web browser.
Solution / Fix
Sun Cobalt RaQ Service.CGI HTTP Server Denial of Service Vulnerablity
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Sun Cobalt RaQ Service.CGI HTTP Server Denial of Service Vulnerablity
References:
References: