Pserv HTTP Version Specifier Buffer Overflow Vulnerability
BID:6285
Info
Pserv HTTP Version Specifier Buffer Overflow Vulnerability
| Bugtraq ID: | 6285 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 30 2002 12:00AM |
| Updated: | Nov 30 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to "Matthew Murphy" <[email protected]>. |
| Vulnerable: |
Pserv Pserv 2.0 beta 5 Pserv Pserv 2.0 beta 3 Pserv Pserv 2.0 beta 2 Pserv Pserv 2.0 beta 1 |
| Not Vulnerable: | |
Discussion
Pserv HTTP Version Specifier Buffer Overflow Vulnerability
A buffer overflow vulnerability has been reported in Pserv. The buffer overflow condition is due to the way Pserv handles data streams from remote connections.
An attacker can exploit this vulnerability by issuing a HTTP request with an invalid HTTP version specifier. Due to insufficient buffers being allocated when processing the data, it may be possible to corrupt sensitive memory on the system stack.
A buffer overflow vulnerability has been reported in Pserv. The buffer overflow condition is due to the way Pserv handles data streams from remote connections.
An attacker can exploit this vulnerability by issuing a HTTP request with an invalid HTTP version specifier. Due to insufficient buffers being allocated when processing the data, it may be possible to corrupt sensitive memory on the system stack.
Exploit / POC
Pserv HTTP Version Specifier Buffer Overflow Vulnerability
The following proof of concept was provided:
GET / HTTP/1.[buffer]
The following proof of concept was provided:
GET / HTTP/1.[buffer]
Solution / Fix
Pserv HTTP Version Specifier Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.