Pserv HTTP POST Request Buffer Overflow Vulnerability
BID:6242
Info
Pserv HTTP POST Request Buffer Overflow Vulnerability
| Bugtraq ID: | 6242 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 25 2002 12:00AM |
| Updated: | Nov 25 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to "dong-h0un U" <[email protected]>. |
| Vulnerable: |
Pserv Pserv 2.0 beta 3 Pserv Pserv 2.0 beta 2 Pserv Pserv 2.0 beta 1 |
| Not Vulnerable: | |
Discussion
Pserv HTTP POST Request Buffer Overflow Vulnerability
A buffer overflow vulnerability has been reported in Pserv. Reportedly, it is possible to overflow a local buffer by constructing a malicious HTTP request.
An attacker can exploit this vulnerability by crafting a malicious HTTP POST request and submitting it to the vulnerable server. This will trigger the overflow condition which may cause memory to be corrupted.
Exploitation of this issue will result in a denial of service. Although it has not been confirmed, it may be possible for an attacker to execute arbitrary code.
A buffer overflow vulnerability has been reported in Pserv. Reportedly, it is possible to overflow a local buffer by constructing a malicious HTTP request.
An attacker can exploit this vulnerability by crafting a malicious HTTP POST request and submitting it to the vulnerable server. This will trigger the overflow condition which may cause memory to be corrupted.
Exploitation of this issue will result in a denial of service. Although it has not been confirmed, it may be possible for an attacker to execute arbitrary code.
Solution / Fix
Pserv HTTP POST Request Buffer Overflow Vulnerability
Solution:
An unofficial patch has been provided by "dong-h0un U" <[email protected]>. Further information is available in the referenced message.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
An unofficial patch has been provided by "dong-h0un U" <[email protected]>. Further information is available in the referenced message.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Pserv HTTP POST Request Buffer Overflow Vulnerability
References:
References:
- Pserv Home Page (Pserv)
- Remote POST Buffer Overflow vulnerability in Pserv. ("dong-h0un U"
)