Surfboard httpd Remote Buffer Overflow Vulnerability
BID:9299
Info
Surfboard httpd Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 9299 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 26 2003 12:00AM |
| Updated: | Dec 26 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to decka trash <[email protected]>. |
| Vulnerable: |
Surfboard Surfboard httpd 1.1.9 |
| Not Vulnerable: | |
Discussion
Surfboard httpd Remote Buffer Overflow Vulnerability
It has been reported that Surfboard httpd is prone to a remote buffer overflow condition that may allow an attacker to gain unauthorized access to a system running the vulnerable software. The issue presents itself when an attacker sends a specially crafted URL request with more than 1024 characters to the server daemon.
Surfboard version 1.1.9 has been reported to be prone to this issue, however, other versions may be affected as well.
It has been reported that Surfboard httpd is prone to a remote buffer overflow condition that may allow an attacker to gain unauthorized access to a system running the vulnerable software. The issue presents itself when an attacker sends a specially crafted URL request with more than 1024 characters to the server daemon.
Surfboard version 1.1.9 has been reported to be prone to this issue, however, other versions may be affected as well.
Exploit / POC
Surfboard httpd Remote Buffer Overflow Vulnerability
The following proof of concept has been supplied:
GET /AAAAAAAAAAAA..x1024++ HTTP/1.1\r\n\r\n
The following proof of concept has been supplied:
GET /AAAAAAAAAAAA..x1024++ HTTP/1.1\r\n\r\n
Solution / Fix
Surfboard httpd Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Surfboard httpd Remote Buffer Overflow Vulnerability
References:
References:
- Surfboard Homepage (Surfboard)
- Surfboard httpd Buffer Overflow May Allow a Remote User to Execute Arbitrary Cod (SecurityTracker)