Softrex Tornado WWW-Server Buffer Overflow Vulnerability
BID:7716
Info
Softrex Tornado WWW-Server Buffer Overflow Vulnerability
| Bugtraq ID: | 7716 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 28 2003 12:00AM |
| Updated: | May 28 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to D4rkGr3y <[email protected]>. |
| Vulnerable: |
Softrex Tornado www-Server 1.2 |
| Not Vulnerable: | |
Discussion
Softrex Tornado WWW-Server Buffer Overflow Vulnerability
A buffer overflow vulnerability has been reported for Tornado www-Server. The vulnerability exists when Tornado processes overly long HTTP requests. This will result in the server crashing.
Although unconfirmed, it may be possible to exploit this vulnerability to execute malicious attacker-supplied code.
A buffer overflow vulnerability has been reported for Tornado www-Server. The vulnerability exists when Tornado processes overly long HTTP requests. This will result in the server crashing.
Although unconfirmed, it may be possible to exploit this vulnerability to execute malicious attacker-supplied code.
Exploit / POC
Softrex Tornado WWW-Server Buffer Overflow Vulnerability
The following proof of concept was provided:
http://www.example.com/aaa[471]aaa
The following proof of concept was provided:
http://www.example.com/aaa[471]aaa
Solution / Fix
Softrex Tornado WWW-Server Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Softrex Tornado WWW-Server Buffer Overflow Vulnerability
References:
References:
- Tornado www-Server (Softrex)
- Tornado www-server v1.2: directory traversal, buffer overflow (D4rkGr3y
)