Mod_Mylo Apache Module REQSTR Buffer Overflow Vulnerability
BID:8287
Info
Mod_Mylo Apache Module REQSTR Buffer Overflow Vulnerability
| Bugtraq ID: | 8287 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0651 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 28 2003 12:00AM |
| Updated: | Jul 11 2009 10:56PM |
| Credit: | Discovery of this vulnerability has been credited to Carl Livitt <[email protected]>. |
| Vulnerable: |
mod_mylo mod_mylo 2.1 mod_mylo mod_mylo 2.0 mod_mylo mod_mylo 0.1 |
| Not Vulnerable: |
mod_mylo mod_mylo 2.2 |
Discussion
Mod_Mylo Apache Module REQSTR Buffer Overflow Vulnerability
mod_mylo has been reported prone to remotely exploitable buffer overflow vulnerability.
The issue presents itself due to insufficient bounds checking performed on HTTP requests before the HTTP request string is copied into a buffer in memory. A remote attacker may exploit this condition to execute arbitrary instructions in the context of the Apache HTTP server.
This issue has been reported to affect mod_mylo version 0.2.1 and all versions prior.
mod_mylo has been reported prone to remotely exploitable buffer overflow vulnerability.
The issue presents itself due to insufficient bounds checking performed on HTTP requests before the HTTP request string is copied into a buffer in memory. A remote attacker may exploit this condition to execute arbitrary instructions in the context of the Apache HTTP server.
This issue has been reported to affect mod_mylo version 0.2.1 and all versions prior.