PT-2016-7778 · Boa · Boa Web Server
Published
2016-11-30
·
Updated
2024-02-14
·
CVE-2016-9564
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Boa Webserver version 0.92r
Description
The issue is related to a buffer overflow in the send redirect() function, which can be triggered by remote attackers through an HTTP GET request. This request must contain a long URI with only '/' and '.' characters, leading to a denial of service (DoS).
Recommendations
For Boa Webserver version 0.92r, consider restricting access to the send redirect() function until a patch is available. As a temporary workaround, limit the length of URIs that can be processed by the server to prevent the buffer overflow.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Boa Web Server