MDG Web Server 4D HTTP Command Buffer Overflow Vulnerability
BID:7479
Info
MDG Web Server 4D HTTP Command Buffer Overflow Vulnerability
| Bugtraq ID: | 7479 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 01 2003 12:00AM |
| Updated: | May 01 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to "tom ferris" <[email protected]>. |
| Vulnerable: |
MDG Computer Services Web Server 4D 3.6 |
| Not Vulnerable: | |
Discussion
MDG Web Server 4D HTTP Command Buffer Overflow Vulnerability
A buffer overflow vulnerability has been reported for MDG Web Server. The vulnerability exists when the web server attempts to process overly long HTTP requests. Specifically, when the web server processes a malformed HTTP request of excessive length, the web server will crash. This will result in a denial of service condition.
A buffer overflow vulnerability has been reported for MDG Web Server. The vulnerability exists when the web server attempts to process overly long HTTP requests. Specifically, when the web server processes a malformed HTTP request of excessive length, the web server will crash. This will result in a denial of service condition.
Exploit / POC
MDG Web Server 4D HTTP Command Buffer Overflow Vulnerability
Exploit code has been released.
Exploit code has been released.
Solution / Fix
MDG Web Server 4D HTTP Command Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
MDG Web Server 4D HTTP Command Buffer Overflow Vulnerability
References:
References:
- MDG Homepage (MDG Computer Services)
- SP Research Labs Advisory x05 ("tom ferris"
)