PT-2006-6523 · Essentia · Essentia Web Server
Corryl
·
Published
2006-11-10
·
Updated
2018-10-17
·
CVE-2006-5850
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Essentia Web Server version 2.15
Description
A stack-based buffer overflow issue allows remote attackers to execute arbitrary code via a long URI, as demonstrated by a GET or HEAD request to API endpoints such as "/api/v1/login" or "/users/{id}". This can be achieved by manipulating the
uri variable.Recommendations
For Essentia Web Server version 2.15, update to a newer version that contains a fix for this issue. As a temporary workaround, consider restricting access to API endpoints that may be vulnerable to buffer overflow attacks until a patch is available. Avoid using long URIs in requests to the server until the issue is resolved.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Essentia Web Server