Abyss Web Server HTTP GET Heap Overrun Vulnerability
BID:8062
Info
Abyss Web Server HTTP GET Heap Overrun Vulnerability
| Bugtraq ID: | 8062 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 30 2003 12:00AM |
| Updated: | Jun 30 2003 12:00AM |
| Credit: | Discovery of this issue is credited to Fozzy <[email protected]>. |
| Vulnerable: |
Aprelium Technologies Abyss Web Server 1.1.2 |
| Not Vulnerable: |
Aprelium Technologies Abyss Web Server 1.1.6 Beta |
Discussion
Abyss Web Server HTTP GET Heap Overrun Vulnerability
Abyss Web Server is prone to a remotely exploitable heap overrun. This is due to insufficient bounds checking of data supplied via client HTTP GET requests. This condition could be exploited to execute arbitrary code with the privileges of the web server.
This issue is reported to affect Abyss Web Server 1.1.2. Later versions, such as 1.1.4 and 1.1.5 may be similarly affected, though this has not been confirmed.
Abyss Web Server is prone to a remotely exploitable heap overrun. This is due to insufficient bounds checking of data supplied via client HTTP GET requests. This condition could be exploited to execute arbitrary code with the privileges of the web server.
This issue is reported to affect Abyss Web Server 1.1.2. Later versions, such as 1.1.4 and 1.1.5 may be similarly affected, though this has not been confirmed.
Solution / Fix
Abyss Web Server HTTP GET Heap Overrun Vulnerability
Solution:
This issue is reportedly fixed in Abyss Web Server 1.1.6. Users should contact the vendor to obtain upgrades.
Solution:
This issue is reportedly fixed in Abyss Web Server 1.1.6. Users should contact the vendor to obtain upgrades.
References
Abyss Web Server HTTP GET Heap Overrun Vulnerability
References:
References:
- Abyss Web Server Homepage (Aprelium Technologies)