Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.800962
Kategorie:Buffer overflow
Titel:httpdx Web Server 'h_handlepeer()' Buffer Overflow Vulnerability
Zusammenfassung:The host is running httpdx Web Server and is prone to a Buffer; Overflow vulnerability.
Beschreibung:Summary:
The host is running httpdx Web Server and is prone to a Buffer
Overflow vulnerability.

Vulnerability Insight:
A boundary error occurs in 'h_handlepeer()' in 'http.cpp' while processing
overly long HTTP requests leading to a buffer overflow.

Vulnerability Impact:
Remote attackers can exploit this issue to execute arbitrary code or crash
the server via a specially crafted request.

Affected Software/OS:
httpdx Web Server version 1.4.3 and prior on windows.

Solution:
Upgrade to httpdx Server version 1.4.4 or later.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2009-3711
Bugtraq: 20091008 Remote buffer overflow in httpdx (Google Search)
http://www.securityfocus.com/archive/1/507042/100/0/threaded
Bugtraq: 20091009 Re: Remote buffer overflow in httpdx (Google Search)
http://www.securityfocus.com/archive/1/507073/100/0/threaded
Bugtraq: 20091010 http://marc.info/?l=bugtraq&m=125544914512291&w=2 (Google Search)
http://marc.info/?l=bugtraq&m=125544914512291&w=2
http://www.pank4j.com/exploits/httpdxb0f.php
http://osvdb.org/58714
http://secunia.com/advisories/36991
http://www.vupen.com/english/advisories/2009/2874
XForce ISS Database: httpdx-hhandlepeer-bo(53700)
https://exchange.xforce.ibmcloud.com/vulnerabilities/53700
CopyrightCopyright (C) 2009 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.