SurfControl SuperScout Email Filter Missing Content-Length HTTP Header Field DoS Vulnerability
BID:5930
Info
SurfControl SuperScout Email Filter Missing Content-Length HTTP Header Field DoS Vulnerability
| Bugtraq ID: | 5930 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2002-1531 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 09 2002 12:00AM |
| Updated: | Jul 11 2009 06:06PM |
| Credit: | Discovery of this issue is credited to "'ken'@FTU" <[email protected]>. |
| Vulnerable: |
SurfControl SuperScout Email Filter for SMTP 4.0 SurfControl SuperScout Email Filter 3.5.1 SurfControl SuperScout Email Filter 3.5 |
| Not Vulnerable: | |
Discussion
SurfControl SuperScout Email Filter Missing Content-Length HTTP Header Field DoS Vulnerability
SurfControl SuperScout Email Filter comes with a web-based interface to provide remote access to administrative facilities.
The administrative web interface is prone to a denial of service when handling a malformed HTTP request. Upon receipt of a request that does not contain a Content-Length HTTP Header field, the administrative interface will crash.
It may be possible for attackers to exploit this condition to execute arbitrary code. This is not confirmed.
SurfControl SuperScout Email Filter comes with a web-based interface to provide remote access to administrative facilities.
The administrative web interface is prone to a denial of service when handling a malformed HTTP request. Upon receipt of a request that does not contain a Content-Length HTTP Header field, the administrative interface will crash.
It may be possible for attackers to exploit this condition to execute arbitrary code. This is not confirmed.
Exploit / POC
SurfControl SuperScout Email Filter Missing Content-Length HTTP Header Field DoS Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
SurfControl SuperScout Email Filter Missing Content-Length HTTP Header Field DoS Vulnerability
Solution:
The vendor has reportedly released a fix. Affected users should contact the vendor about obtaining fixes.
Solution:
The vendor has reportedly released a fix. Affected users should contact the vendor about obtaining fixes.
References
SurfControl SuperScout Email Filter Missing Content-Length HTTP Header Field DoS Vulnerability
References:
References:
- SurfControl Home Page (SurfControl)