PT-2010-1681 · Rhinosoft · Serv-U Web Client

Publicado

2010-05-26

·

Atualizado

2010-05-26

·

CVE-2009-4873

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Serv-U Web Client version 9.0.0.5
Description The issue is a stack-based buffer overflow in the HTTP server of the Serv-U Web Client, which can be exploited by remote attackers. This can lead to a denial of service, causing the server to crash, or potentially allow the execution of arbitrary code. The attack vector involves a long Session cookie.
Recommendations For Serv-U Web Client version 9.0.0.5, consider updating to a newer version that addresses this issue, as using a long Session cookie can trigger the buffer overflow. As a temporary workaround, restrict access to the HTTP server to minimize the risk of exploitation. Avoid using excessively long Session cookies in the affected API endpoint until the issue is resolved.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-4873

Produtos afetados

Serv-U Web Client