[NT] SeaNox Devwex Denial of Service and Directory Traversal
From: support@securiteam.comDate: 06/09/02
- Previous message: support@securiteam.com: "[UNIX] Pine Privacy Patch"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: support@securiteam.com To: list@securiteam.com Date: Sun, 9 Jun 2002 17:36:17 +0200 (CEST)
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -
SeaNox Devwex Denial of Service and Directory Traversal
------------------------------------------------------------------------
SUMMARY
<http://www.seanox.de/projects.devwex.php4> DevWex is a small and
flexible Webserver running as standalone Win32 binary and as Java
application. Two security vulnerabilities have been found in the product,
allowing attackers to cause a buffer to overflow and to access files that
reside outside the bounding HTML root directory.
DETAILS
Buffer-overflow problem:
There exists a buffer-overflow problem in the procedure handling the GET
HTTP type request. Sending more than 258383 characters after the GET
request will cause the server to crash.
Example:
GET 258383xA+CRLF+CRLF
Directory traversal:
An attacker can request an URL containing Windows path delimiters to break
out of the document root of DevWex. This allows an attacker to download
sensitive data.
Example:
GET /..\..\..\..\anyfile
ADDITIONAL INFORMATION
The information has been provided by <mailto:iuk@gmx.ch> Kistler Ueli.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: support@securiteam.com: "[UNIX] Pine Privacy Patch"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|