Plug and Play Web Server Remote Denial of Service Vulnerability
BID:8941
Info
Plug and Play Web Server Remote Denial of Service Vulnerability
| Bugtraq ID: | 8941 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 31 2003 12:00AM |
| Updated: | Oct 31 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to Oliver Karow <[email protected]>. |
| Vulnerable: |
Plug and Play Web Server 1.0 002c |
| Not Vulnerable: | |
Discussion
Plug and Play Web Server Remote Denial of Service Vulnerability
It has been reported that Plug and Play server may be prone to a denial of service vulnerability that may allow a remote attacker to cause the software to crash. The issue may be caused by sending the server a "GET /asdf.? HTTP/1.0" HTTP GET request.
This vulnerability may be successfully exploited to cause the software to act in an unstable manner leading to a crash or hang.
Plug and Play version 1.0002c has been reported to be prone to this issue, however other versions may be vulnerable as well.
It has been reported that Plug and Play server may be prone to a denial of service vulnerability that may allow a remote attacker to cause the software to crash. The issue may be caused by sending the server a "GET /asdf.? HTTP/1.0" HTTP GET request.
This vulnerability may be successfully exploited to cause the software to act in an unstable manner leading to a crash or hang.
Plug and Play version 1.0002c has been reported to be prone to this issue, however other versions may be vulnerable as well.
Exploit / POC
Plug and Play Web Server Remote Denial of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Plug and Play Web Server Remote Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Plug and Play Web Server Remote Denial of Service Vulnerability
References:
References:
- Web Server (Plug and Play)
- DoS in Plug and Play Web Server Proxy Server ("Oliver Karow"
)