cgihtml Signed Integer Content-Length Memory Corruption Vulnerability
BID:6551
Info
cgihtml Signed Integer Content-Length Memory Corruption Vulnerability
| Bugtraq ID: | 6551 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 07 2003 12:00AM |
| Updated: | Jan 07 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to Chris Leishman <[email protected]>. |
| Vulnerable: |
Eekim cgihtml 1.69 |
| Not Vulnerable: | |
Discussion
cgihtml Signed Integer Content-Length Memory Corruption Vulnerability
A vulnerability has been discovered in cgihtml which may result in memory corruption. The problem occurs due to a signed Content-Length value. By passing a negative Content-Length value in an HTTP POST request it is possible to trick the function into allocating insufficient memory. When the POST data is read from the user, heap memory will be overwritten causing the process to crash.
Although not yet confirmed it may be possible to exploit this vulnerability to execute arbitrary instructions.
A vulnerability has been discovered in cgihtml which may result in memory corruption. The problem occurs due to a signed Content-Length value. By passing a negative Content-Length value in an HTTP POST request it is possible to trick the function into allocating insufficient memory. When the POST data is read from the user, heap memory will be overwritten causing the process to crash.
Although not yet confirmed it may be possible to exploit this vulnerability to execute arbitrary instructions.
Exploit / POC
cgihtml Signed Integer Content-Length Memory Corruption Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.