TelCondex SimpleWebserver HTTP Referer Remote Buffer Overflow Vulnerability
BID:8925
Info
TelCondex SimpleWebserver HTTP Referer Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 8925 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 29 2003 12:00AM |
| Updated: | Oct 29 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to Oliver Karow <[email protected]>. |
| Vulnerable: |
TelCondex SimpleWebServer 2.12.30210 build 3285 |
| Not Vulnerable: | |
Discussion
TelCondex SimpleWebserver HTTP Referer Remote Buffer Overflow Vulnerability
A vulnerability has been reported in SimpleWebServer that may allow a remote attacker to cause a denial of service condition or execute arbitrary code on vulnerable host. The issue is reported to exist due to a lack of bounds checking by software, leading to a buffer overflow condition. The problem is reported to exist due to the HTTP referer header. It has been reported that an attacker may be able to crash the server by sending 700 bytes of data through the HTTP referer header and overwrite the return address on the stack with 704 bytes.
Successful exploitation of this issue may allow an attacker to cause a denial of service condition or execute arbitrary code in the context of the web server in order to gain unauthorized access to a vulnerable system.
SimpleWebServer version 2.12.30210 Build 3285 has been reported to be prone to this issue, however other versions may be affected as well.
A vulnerability has been reported in SimpleWebServer that may allow a remote attacker to cause a denial of service condition or execute arbitrary code on vulnerable host. The issue is reported to exist due to a lack of bounds checking by software, leading to a buffer overflow condition. The problem is reported to exist due to the HTTP referer header. It has been reported that an attacker may be able to crash the server by sending 700 bytes of data through the HTTP referer header and overwrite the return address on the stack with 704 bytes.
Successful exploitation of this issue may allow an attacker to cause a denial of service condition or execute arbitrary code in the context of the web server in order to gain unauthorized access to a vulnerable system.
SimpleWebServer version 2.12.30210 Build 3285 has been reported to be prone to this issue, however other versions may be affected as well.
Exploit / POC
TelCondex SimpleWebserver HTTP Referer Remote Buffer Overflow Vulnerability
A proof of concept exploit designed to trigger a denial of service has been made available. Exploit code to execute code has not yet been made available.
A proof of concept exploit designed to trigger a denial of service has been made available. Exploit code to execute code has not yet been made available.
Solution / Fix
TelCondex SimpleWebserver HTTP Referer Remote Buffer Overflow Vulnerability
Solution:
The vendor has released a fixed version (2.13) to address this issue:
TelCondex SimpleWebServer 2.12.30210 build 3285
Solution:
The vendor has released a fixed version (2.13) to address this issue:
TelCondex SimpleWebServer 2.12.30210 build 3285
-
TelCondex TcSimpleWebServer2000Setup.exe
http://www.yourinfosystem.de/download/TcSimpleWebServer2000Setup.exe
References
TelCondex SimpleWebserver HTTP Referer Remote Buffer Overflow Vulnerability
References:
References:
- YourInfoSystem Home Page (TelCondex Software)
- TelCondex SimpleWebserver Buffer Overflow ("Oliver Karow"
)