PT-2002-1257 · Mandrake · Webalizer
Published
2002-04-18
·
Updated
2017-07-11
·
CVE-2002-0180
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Webalizer versions 2.01 through 2.06
Description
A buffer overflow issue exists when Webalizer is configured to use reverse DNS lookups. This allows remote attackers to execute arbitrary code by connecting to the monitored web server from an IP address that resolves to a long hostname.
Recommendations
For Webalizer versions 2.01 through 2.06, consider disabling the reverse DNS lookup feature as a temporary workaround until a patch is available. Restrict access to the monitored web server to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Webalizer