Seminole Webserver Invalid Request Heap Corruption Vulnerability
BID:4728
Info
Seminole Webserver Invalid Request Heap Corruption Vulnerability
| Bugtraq ID: | 4728 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 11 2002 12:00AM |
| Updated: | May 11 2002 12:00AM |
| Credit: | Published in the Seminole Webserver Changelog. |
| Vulnerable: |
Mark Grosberg Seminole Webserver 2.10 |
| Not Vulnerable: |
Mark Grosberg Seminole Webserver 2.12 |
Discussion
Seminole Webserver Invalid Request Heap Corruption Vulnerability
Seminole Webserver is a small web server designed specifically for embedded systems.
A vulnerability has been reported in the handling of some invalid HTTP requests by Seminole Webserver. Under some circumstances, an invalid request may result in a buffer stored in heap memory being freed twice. Execution of arbitrary code may be possible.
Seminole Webserver is a small web server designed specifically for embedded systems.
A vulnerability has been reported in the handling of some invalid HTTP requests by Seminole Webserver. Under some circumstances, an invalid request may result in a buffer stored in heap memory being freed twice. Execution of arbitrary code may be possible.
Exploit / POC
Seminole Webserver Invalid Request Heap Corruption Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Seminole Webserver Invalid Request Heap Corruption Vulnerability
Solution:
An updated version is available:
Mark Grosberg Seminole Webserver 2.10
Solution:
An updated version is available:
Mark Grosberg Seminole Webserver 2.10
-
Mark Grosberg seminole-2.12.tar.gz
http://freshmeat.net/redir/seminole/19624/url_tgz/seminole-2.12.tar.gz
References
Seminole Webserver Invalid Request Heap Corruption Vulnerability
References:
References:
- The Seminole Webserver (Mark Grosberg)