PT-2010-2309 · Geo++ · Geo++ Gncaster
Published
2010-02-04
·
Updated
2018-10-10
·
CVE-2010-0552
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Geo++ GNCASTER versions 1.4.0.7 and earlier
Description
The issue allows remote attackers to cause a denial of service, resulting in an application crash, and possibly execute arbitrary code. This can be achieved by sending multiple requests for a non-existent file using a long URI.
Recommendations
For Geo++ GNCASTER versions 1.4.0.7 and earlier, consider restricting access to the application until a fix is available to prevent potential denial of service and code execution attacks. As a temporary workaround, limit the length of accepted URIs to prevent crashes from long URI requests.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Geo++ Gncaster