Radiobird Software WebServer 4 All Host Field Header Buffer Overflow Vulnerability
BID:6034
Info
Radiobird Software WebServer 4 All Host Field Header Buffer Overflow Vulnerability
| Bugtraq ID: | 6034 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 23 2002 12:00AM |
| Updated: | Oct 23 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to Tamer Sahin <[email protected]>. |
| Vulnerable: |
RadioBird Software WebServer 4 All 1.28 |
| Not Vulnerable: |
RadioBird Software WebServer 4 All 1.32 |
Discussion
Radiobird Software WebServer 4 All Host Field Header Buffer Overflow Vulnerability
A buffer overflow vulnerability has been reported for WebServer 4 All. The vulnerability is due to inadequate bounds checking on the 'Host:' HTTP header field.
Although unconfirmed, it may be possible for a remote attacker to exploit this issue to execute arbitrary system commands with the privileges of the WebServer 4 All process.
A buffer overflow vulnerability has been reported for WebServer 4 All. The vulnerability is due to inadequate bounds checking on the 'Host:' HTTP header field.
Although unconfirmed, it may be possible for a remote attacker to exploit this issue to execute arbitrary system commands with the privileges of the WebServer 4 All process.
Exploit / POC
Radiobird Software WebServer 4 All Host Field Header Buffer Overflow Vulnerability
A proof of concept has been provided by Tamer Sahin and can be found in the referenced message.
A proof of concept has been provided by Tamer Sahin and can be found in the referenced message.
Solution / Fix
Radiobird Software WebServer 4 All Host Field Header Buffer Overflow Vulnerability
Solution:
The following fixes are available:
RadioBird Software WebServer 4 All 1.28
Solution:
The following fixes are available:
RadioBird Software WebServer 4 All 1.28
-
RadioBird Software WebServer 4 All 1.32
ftp://ftp.freeware.lt/anonymous/Soft/w4asetup.exe
References
Radiobird Software WebServer 4 All Host Field Header Buffer Overflow Vulnerability
References:
References:
- Home Page (RadioBird Software)