Pserv流读取缓冲区溢出漏洞

Pserv流读取缓冲区溢出漏洞

漏洞ID 1107120 漏洞类型 缓冲区溢出
发布时间 2002-11-30 更新时间 2002-12-31
图片[1]-Pserv流读取缓冲区溢出漏洞-安全小百科CVE编号 CVE-2002-2295
图片[2]-Pserv流读取缓冲区溢出漏洞-安全小百科CNNVD-ID CNNVD-200212-546
漏洞平台 Linux CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/22056
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200212-546
|漏洞详情
PicoServer(pServ)2.0beta1版本到beta5版本存在缓冲区溢出漏洞。远程攻击者可以借助(1)触发一位偏移缓冲区溢出的1024字节TCP流消息,或(2)HTTP请求的超长方式名,(3)HTTP请求的超长版本号,(4)超长User-Agent标题,或(5)超长文件路径导致服务拒绝(崩溃)并且可能执行任意代码。
|漏洞EXP
source: http://www.securityfocus.com/bid/6285/info

A buffer overflow vulnerability has been reported in Pserv. The buffer overflow condition is due to the way Pserv handles data streams from remote connections. 

An attacker can exploit this vulnerability by issuing a HTTP request with an invalid HTTP version specifier. Due to insufficient buffers being allocated when processing the data, it may be possible to corrupt sensitive memory on the system stack.

GET / HTTP/1.[buffer]
|参考资料

来源:XF
名称:pserv-version-specifier-bo(10789)
链接:http://xforce.iss.net/xforce/xfdb/10789
来源:XF
名称:pserv-data-stream-bo(10783)
链接:http://xforce.iss.net/xforce/xfdb/10783
来源:XF
名称:pserv-http-bo(10734)
链接:http://xforce.iss.net/xforce/xfdb/10734
来源:BID
名称:6285
链接:http://www.securityfocus.com/bid/6285
来源:BID
名称:6284
链接:http://www.securityfocus.com/bid/6284
来源:BID
名称:6283
链接:http://www.securityfocus.com/bid/6283
来源:www.securiteam.com
链接:http://www.securiteam.com/securitynews/6Q0020A6AS.html
来源:BUGTRAQ
名称:20021201MultiplepServRemoteBufferOverflowVulnerabilities
链接:http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2002-12/0005.html
来源:FULLDISC
名称:20021130MultiplepServRemoteBufferOverflowVulnerabilities
链接:http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2002-11/0457.html

相关推荐: AIX ping缓冲区溢出漏洞

AIX ping缓冲区溢出漏洞 漏洞ID 1105324 漏洞类型 缓冲区溢出 发布时间 1997-07-21 更新时间 1997-07-21 CVE编号 CVE-1999-1208 CNNVD-ID CNNVD-199707-033 漏洞平台 AIX CVS…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享