PT-2007-4306 · Embedthis · Mbedthis Appweb

Publicado

2007-06-04

·

Atualizado

2011-03-08

·

CVE-2007-3009

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: Mbedthis AppWeb version 2.0.5-4
Description: The issue is related to a format string vulnerability in the MprLogToFile::logEvent function. This vulnerability can be exploited by remote attackers to cause a denial of service, resulting in a daemon crash. The exploitation is possible when the build supports logging, but the configuration disables logging. Attackers can send HTTP requests with format string specifiers in the scheme to trigger the vulnerability, as demonstrated by a "GET %n://localhost:80/" request.
Recommendations: For Mbedthis AppWeb version 2.0.5-4, consider disabling the logging functionality temporarily to prevent exploitation until a patch is available. Additionally, restrict access to the MprLogToFile::logEvent function to minimize the risk of a denial of service attack. Avoid using format string specifiers in the HTTP scheme to prevent triggering the vulnerability.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-3009

Produtos afetados

Mbedthis Appweb