Netscape FastTrack Server GET Buffer Overflow Vulnerability
BID:908
Info
Netscape FastTrack Server GET Buffer Overflow Vulnerability
| Bugtraq ID: | 908 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 31 1999 12:00AM |
| Updated: | Dec 31 1999 12:00AM |
| Credit: | First posted to Bugtraq by Brock Tellier <[email protected]> on December 31, 1999. |
| Vulnerable: |
Netscape FastTrack Server 2.0.1 a |
| Not Vulnerable: | |
Discussion
Netscape FastTrack Server GET Buffer Overflow Vulnerability
The version of Netscape FastTrack server that ships with UnixWare 7.1 is vulnerable to a remote buffer overlow. By default, the httpd listens on port 457 of the UnixWare host and serves documentation via http. If you pass the server a GET request with more than 367 characters, the stack overflows and the EIP is overwritten making it possible to execute arbitrary code with the privileges of the httpd (usually nobody).
The version of Netscape FastTrack server that ships with UnixWare 7.1 is vulnerable to a remote buffer overlow. By default, the httpd listens on port 457 of the UnixWare host and serves documentation via http. If you pass the server a GET request with more than 367 characters, the stack overflows and the EIP is overwritten making it possible to execute arbitrary code with the privileges of the httpd (usually nobody).