PT-2010-3673 · Sblim · Sblim-Sfcb
Chris Buccella
·
Published
2010-06-14
·
Updated
2023-02-13
·
CVE-2010-2054
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SBLIM SFCB versions 1.3.4 through 1.3.7
Description
The issue is related to an integer overflow in the httpAdapter.c component of SBLIM SFCB. This occurs when the configuration sets httpMaxContentLength to a zero value, allowing remote attackers to potentially cause a denial of service or execute arbitrary code by sending a large integer in the Content-Length HTTP header.
Recommendations
For SBLIM SFCB versions 1.3.4 through 1.3.7, consider setting a non-zero value for httpMaxContentLength to prevent exploitation. Additionally, as a temporary workaround, restrict access to the httpAdapter component until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sblim-Sfcb