OmniHTTPD Long Request Buffer Overflow Vulnerability
BID:5136
Info
OmniHTTPD Long Request Buffer Overflow Vulnerability
| Bugtraq ID: | 5136 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 01 2002 12:00AM |
| Updated: | Jul 01 2002 12:00AM |
| Credit: | Discovery of this issue is credited to "Martin J. Muench" <[email protected]>. |
| Vulnerable: |
Omnicron OmniHTTPD 2.0 9 |
| Not Vulnerable: | |
Discussion
OmniHTTPD Long Request Buffer Overflow Vulnerability
OmniHTTPD is prone to a remotely exploitable buffer overflow condition. This problem is in the handling of requests containing overly long headers.
Exploitation of this issue may cause a denial of service condition or result in execution of arbitrary attacker-supplied instructions with the privileges of the webserver process.
This issue was reported in version 2.09 of the software. Other versions may also be affected.
OmniHTTPD is prone to a remotely exploitable buffer overflow condition. This problem is in the handling of requests containing overly long headers.
Exploitation of this issue may cause a denial of service condition or result in execution of arbitrary attacker-supplied instructions with the privileges of the webserver process.
This issue was reported in version 2.09 of the software. Other versions may also be affected.
Exploit / POC
OmniHTTPD Long Request Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
OmniHTTPD Long Request Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
OmniHTTPD Long Request Buffer Overflow Vulnerability
References:
References:
- Omnicron Homepage (Omnicron Technologies Corporation)