Webster HTTP Server Long Request Buffer Overrun Vulnerability
BID:6289
Info
Webster HTTP Server Long Request Buffer Overrun Vulnerability
| Bugtraq ID: | 6289 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 02 2002 12:00AM |
| Updated: | Dec 02 2002 12:00AM |
| Credit: | Discovery of this vulnerability is credited to "Matthew Murphy" <[email protected]>. |
| Vulnerable: |
Webster Webster HTTP Server |
| Not Vulnerable: | |
Discussion
Webster HTTP Server Long Request Buffer Overrun Vulnerability
A buffer overrun has been discovered in Webster HTTP server when processing malicious URLs. It is possible to trigger this vulnerability by passing an affected server a malconstructed URL of excessive length.
Successful exploitation of this issue may allow an attacker to overwrite sensitive locations in memory with malicious values. This may result in the execution of arbitrary code with the privileges of Webster.
A buffer overrun has been discovered in Webster HTTP server when processing malicious URLs. It is possible to trigger this vulnerability by passing an affected server a malconstructed URL of excessive length.
Successful exploitation of this issue may allow an attacker to overwrite sensitive locations in memory with malicious values. This may result in the execution of arbitrary code with the privileges of Webster.
Exploit / POC
Webster HTTP Server Long Request Buffer Overrun Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Webster HTTP Server Long Request Buffer Overrun Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.