PT-2002-1257 · Mandrake · Webalizer
Publicado
2002-04-18
·
Atualizado
2017-07-11
·
CVE-2002-0180
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Webalizer versions 2.01 through 2.06
Description
A buffer overflow issue exists when Webalizer is configured to use reverse DNS lookups. This allows remote attackers to execute arbitrary code by connecting to the monitored web server from an IP address that resolves to a long hostname.
Recommendations
For Webalizer versions 2.01 through 2.06, consider disabling the reverse DNS lookup feature as a temporary workaround until a patch is available. Restrict access to the monitored web server to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Webalizer