Polycom ViaVideo缓冲区溢出漏洞

Polycom ViaVideo缓冲区溢出漏洞

漏洞ID 1107043 漏洞类型 缓冲区溢出
发布时间 2002-10-15 更新时间 2005-10-20
图片[1]-Polycom ViaVideo缓冲区溢出漏洞-安全小百科CVE编号 CVE-2002-1905
图片[2]-Polycom ViaVideo缓冲区溢出漏洞-安全小百科CNNVD-ID CNNVD-200212-435
漏洞平台 Windows CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/21941
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200212-435
|漏洞详情
PolycomViaVideo2.2和3.0版本的web服务器中存在缓冲区溢出漏洞。远程攻击者借助超长HTTPGET请求导致服务拒绝(崩溃)。
|漏洞EXP
source: http://www.securityfocus.com/bid/5964/info

A buffer overflow vulnerability has been reported for ViaVideo.

An attacker can exploit this vulnerability by issuing excessively long 'GET' requests to ViaVideo devices. This will cause an error in the 'vvws.dll' library and will cause the ViaVideo service to crash.

Although unconfirmed, it may be possible for a remote attacker to exploit this issue to execute arbitrary system commands with the privileges of the ViaVideo process. 

perl -e 'print "GET " . "A" x 4132 . " HTTP/1.0rnrn";' | netcat 10.1.0.1 3603
|参考资料

来源:BID
名称:5964
链接:http://www.securityfocus.com/bid/5964
来源:XF
名称:viavideo-webserver-get-bo(10359)
链接:http://www.iss.net/security_center/static/10359.php

相关推荐: X-News权限漏洞

X-News权限漏洞 漏洞ID 1203229 漏洞类型 未知 发布时间 2002-12-31 更新时间 2002-12-31 CVE编号 CVE-2002-2046 CNNVD-ID CNNVD-200212-720 漏洞平台 N/A CVSS评分 7.5 …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享