Null HTTPd Remote Heap Overflow Vulnerability
BID:5774
Info
Null HTTPd Remote Heap Overflow Vulnerability
| Bugtraq ID: | 5774 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-1496 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 23 2002 12:00AM |
| Updated: | Jul 11 2009 05:06PM |
| Credit: | Discovery credited to Netric Security Team. |
| Vulnerable: |
NullLogic Null HTTPd 0.5.1 NullLogic Null HTTPd 0.5 |
| Not Vulnerable: |
NullLogic Null HTTPd 0.5.1 |
Discussion
Null HTTPd Remote Heap Overflow Vulnerability
Null httpd is a small multithreaded web server for Linux and Windows, mantained by NullLogic.
A remotely exploitable heap overflow has been discovered in Null httpd. By passing a negative content length value to the server, it is possible to modify the allocation size of the read buffer, resulting in a heap overflow.
An attacker may exploit this condition to overwrite arbitrary words in memory through the free() function. This may allow for the execution of arbitrary code.
It should be noted that although reported on v0.5.0, earlier versions are likely vulnerable.
Null httpd is a small multithreaded web server for Linux and Windows, mantained by NullLogic.
A remotely exploitable heap overflow has been discovered in Null httpd. By passing a negative content length value to the server, it is possible to modify the allocation size of the read buffer, resulting in a heap overflow.
An attacker may exploit this condition to overwrite arbitrary words in memory through the free() function. This may allow for the execution of arbitrary code.
It should be noted that although reported on v0.5.0, earlier versions are likely vulnerable.