libcsoap 'nanohttp-server.c' Buffer Overflow and Denial of Service Vulnerabilities
BID:72767
Info
libcsoap 'nanohttp-server.c' Buffer Overflow and Denial of Service Vulnerabilities
| Bugtraq ID: | 72767 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 17 2015 12:00AM |
| Updated: | Feb 17 2015 12:00AM |
| Credit: | Patrick Coleman |
| Vulnerable: |
NanoHttpd nanohttpd 0 csoap libcsoap 1.1.0-17.1 |
| Not Vulnerable: |
csoap libcsoap 1.1.0-17.2 |
Discussion
libcsoap 'nanohttp-server.c' Buffer Overflow and Denial of Service Vulnerabilities
libcsoap is prone to a buffer-overflow vulnerability and a denial-of-service vulnerability.
Remote attackers can exploit these issues to execute arbitrary code in the context of the application or cause denial-of-service conditions.
libcsoap is prone to a buffer-overflow vulnerability and a denial-of-service vulnerability.
Remote attackers can exploit these issues to execute arbitrary code in the context of the application or cause denial-of-service conditions.
Exploit / POC
libcsoap 'nanohttp-server.c' Buffer Overflow and Denial of Service Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
libcsoap 'nanohttp-server.c' Buffer Overflow and Denial of Service Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
libcsoap 'nanohttp-server.c' Buffer Overflow and Denial of Service Vulnerabilities
References:
References:
- libsoap Download page (csoap)
- NanoHttpd Home Page (GitHub)
- CVE request: vulnerabilities in libcsoap (Seclists.org)