AnalogX SimpleServer:WWW Web Server Buffer Overflow Vulnerability
BID:5006
Info
AnalogX SimpleServer:WWW Web Server Buffer Overflow Vulnerability
| Bugtraq ID: | 5006 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 13 2002 12:00AM |
| Updated: | Jun 13 2002 12:00AM |
| Credit: | Credited to Fort _ <[email protected]>. |
| Vulnerable: |
AnalogX SimpleServer:WWW 1.16 |
| Not Vulnerable: | |
Discussion
AnalogX SimpleServer:WWW Web Server Buffer Overflow Vulnerability
Reportedly, version 1.16 of SimpleServer:WWW is prone to a buffer overflow vulnerability.
A remote attacker is able to connect to SimpleServer via telnet and makes an invalid request to the server. This will cause the web server to crash and potentially lead to a buffer overflow condition.
This issue was originally reported as a denial of service, however, it has been reported possible to initiate a buffer overflow condition.
Reportedly, version 1.16 of SimpleServer:WWW is prone to a buffer overflow vulnerability.
A remote attacker is able to connect to SimpleServer via telnet and makes an invalid request to the server. This will cause the web server to crash and potentially lead to a buffer overflow condition.
This issue was originally reported as a denial of service, however, it has been reported possible to initiate a buffer overflow condition.
Exploit / POC
AnalogX SimpleServer:WWW Web Server Buffer Overflow Vulnerability
Auriemma Luigi <[email protected]>(by way of bugtest <[email protected]>) has provided the following proof of concept which is designed to crash the server and rewrite the EIP with the address of WSACleanup() function.
Auriemma Luigi <[email protected]>(by way of bugtest <[email protected]>) has provided the following proof of concept which is designed to crash the server and rewrite the EIP with the address of WSACleanup() function.
Solution / Fix
AnalogX SimpleServer:WWW Web Server Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
AnalogX SimpleServer:WWW Web Server Buffer Overflow Vulnerability
References:
References:
- SimpleServer:WWW Home Page (AnalogX)