PT-2005-3683 · Bnbt · Bnbt Easytracker

Sowhat

·

Published

2005-09-06

·

Updated

2017-07-11

·

CVE-2005-2806

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions BNBT EasyTracker versions 7.7r3.2004.10.27 and earlier
Description The issue allows remote attackers to cause a denial of service, resulting in an application hang. This can be achieved by sending an HTTP header that contains only a colon (:), which may lead to an integer signedness error due to the absence of a field name or value.
Recommendations For BNBT EasyTracker versions 7.7r3.2004.10.27 and earlier, consider updating to a newer version that addresses this issue. As a temporary workaround, restrict access to the HTTP header processing functionality to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2005-2806

Affected Products

Bnbt Easytracker