Tomahawk Technologies SteelArrow Cookie HTTP Header Buffer Overflow Vulnerability
BID:5494
Info
Tomahawk Technologies SteelArrow Cookie HTTP Header Buffer Overflow Vulnerability
| Bugtraq ID: | 5494 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-1441 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 19 2002 12:00AM |
| Updated: | Jul 11 2009 03:56PM |
| Credit: | Discovery credited to Mark Litchfield of "NGSSoftware Insight Security Research" <[email protected]>. |
| Vulnerable: |
Tomahawk Technologies SteelArrow Web Application Server 4.1 |
| Not Vulnerable: | |
Discussion
Tomahawk Technologies SteelArrow Cookie HTTP Header Buffer Overflow Vulnerability
Reportedly, SteelArrow suffers from a buffer overflow condition when cookies are used. SteelArrow keeps records of user sessions using cookies. It is possible for an attacker to supply an overly long value of the Cookie HTTP header that will cause the buffer overflow condition. This will cause the SteelArrow service to crash and overwrite stack memory with attacker supplied values.
Reportedly, SteelArrow suffers from a buffer overflow condition when cookies are used. SteelArrow keeps records of user sessions using cookies. It is possible for an attacker to supply an overly long value of the Cookie HTTP header that will cause the buffer overflow condition. This will cause the SteelArrow service to crash and overwrite stack memory with attacker supplied values.
Exploit / POC
Tomahawk Technologies SteelArrow Cookie HTTP Header Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Tomahawk Technologies SteelArrow Cookie HTTP Header Buffer Overflow Vulnerability
Solution:
It has been reported that a vendor update is available, however Symantec has been unable to verify this. Customers may wish to contact the vendor for upgrade information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It has been reported that a vendor update is available, however Symantec has been unable to verify this. Customers may wish to contact the vendor for upgrade information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Tomahawk Technologies SteelArrow Cookie HTTP Header Buffer Overflow Vulnerability
References:
References:
- Steel Arrow Home Page (Tomahawk Technologies)