Microsoft Foundation Class Library ISAPI Buffer Overflow Vulnerability
BID:5188
Info
Microsoft Foundation Class Library ISAPI Buffer Overflow Vulnerability
| Bugtraq ID: | 5188 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 08 2002 12:00AM |
| Updated: | Jul 08 2002 12:00AM |
| Credit: | Discovery of this issue is credited to "Matthew Murphy" <[email protected]>. |
| Vulnerable: |
Working Resources Inc. BadBlue Personal Edition 1.7.3 Microsoft Foundation Class Library 7.0 |
| Not Vulnerable: | |
Discussion
Microsoft Foundation Class Library ISAPI Buffer Overflow Vulnerability
The Microsoft Foundation Class Library is a library used to develop applications for Microsoft Windows. Some versions of the MFC include an ISAPI class, which can be used to construct applications which extend web server functionality.
Reportedly, a possible vulnerability exists in some versions of this class. It may be possible to cause a buffer overflow condition in software compiled with vulnerable versions of the library. Exploitation details will vary across different products compiled against the vulnerable library.
This issue may be related to misleading Content-Length headers contained in a HTTP POST request.
This vulnerability was originally believed to be an issue with Working Resources BadBlue web server. In this case, exploitation has been demonstrated to result in a denial of service condition.
The Microsoft Foundation Class Library is a library used to develop applications for Microsoft Windows. Some versions of the MFC include an ISAPI class, which can be used to construct applications which extend web server functionality.
Reportedly, a possible vulnerability exists in some versions of this class. It may be possible to cause a buffer overflow condition in software compiled with vulnerable versions of the library. Exploitation details will vary across different products compiled against the vulnerable library.
This issue may be related to misleading Content-Length headers contained in a HTTP POST request.
This vulnerability was originally believed to be an issue with Working Resources BadBlue web server. In this case, exploitation has been demonstrated to result in a denial of service condition.
Solution / Fix
Microsoft Foundation Class Library ISAPI Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Foundation Class Library ISAPI Buffer Overflow Vulnerability
References:
References:
- BadBlue Product Homepage (Working Resources Inc)
- GeoHttpServer[webcam] Causes MFC42.DLL to overflow ("Rafel Ivgi"
)