BeOS RobinHood RHConsole服务拒绝漏洞

BeOS RobinHood RHConsole服务拒绝漏洞

漏洞ID 1106079 漏洞类型 未知
发布时间 2000-11-14 更新时间 2001-01-09
图片[1]-BeOS RobinHood RHConsole服务拒绝漏洞-安全小百科CVE编号 CVE-2000-1154
图片[2]-BeOS RobinHood RHConsole服务拒绝漏洞-安全小百科CNNVD-ID CNNVD-200101-102
漏洞平台 BeOS CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/20404
https://www.securityfocus.com/bid/88462
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200101-102
|漏洞详情
BeOSr5pro版本及之前版本中RobinHood1.1版本的web服务器的RHConsole存在漏洞。远程攻击者可以借助超长HTTP请求导致服务拒绝。
|漏洞EXP
source : http://www.securityfocus.com/bid/1944/info


RobinHood is a HTTP/1.1 web server based upon libHTTP and is designed for the BeOS platform.

Improper bounds checking exists in code that handles requests (RHCWindow.cpp and RHLogger.cpp). The components RHConsole and RHDaemon will cease operations upon receiving a request consisting of over 4078 bytes. If RobinHood were to encounter such requests repeatedly, a prolonged denial of service attack may result. Restarting the application is required in order to regain normal functionality.


$ telnet target 80
Trying target...
Connected to target.
Escape character is '^]'.
<character string consisting of over 4078 bytes>
|受影响的产品
Joe Kloss RobinHood 1.1
|参考资料

来源:BUGTRAQ
名称:20001113beosvulnerabilities
链接:http://archives.neohapsis.com/archives/bugtraq/2000-11/0203.html

相关推荐: Microsoft IE5 WPAD Spoofing Vulnerability

Microsoft IE5 WPAD Spoofing Vulnerability 漏洞ID 1104479 漏洞类型 Atomicity Error 发布时间 1999-12-02 更新时间 1999-12-02 CVE编号 N/A CNNVD-ID N/A…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享