PT-2010-1681 · Rhinosoft · Serv-U Web Client

Published

2010-05-26

·

Updated

2010-05-26

·

CVE-2009-4873

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Serv-U Web Client version 9.0.0.5
Description The issue is a stack-based buffer overflow in the HTTP server of the Serv-U Web Client, which can be exploited by remote attackers. This can lead to a denial of service, causing the server to crash, or potentially allow the execution of arbitrary code. The attack vector involves a long Session cookie.
Recommendations For Serv-U Web Client version 9.0.0.5, consider updating to a newer version that addresses this issue, as using a long Session cookie can trigger the buffer overflow. As a temporary workaround, restrict access to the HTTP server to minimize the risk of exploitation. Avoid using excessively long Session cookies in the affected API endpoint until the issue is resolved.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-4873

Affected Products

Serv-U Web Client