IBM HTTP Server Denial of Service Vulnerability

IBM HTTP Server is a web server powered by Apache. The Windows NT version is subject to this vulnerability.

IBM HTTP Server is subject to a denial of service. Requesting an unusually long GET request comprised of approx 219 characters will cause the server to stop responding with an error message. A restart of the application is required in order to gain normal functionality.

Successful exploitation of this vulnerability could lead to the execution of arbitrary commands. However this is unverified.

Example of error message provided by benjurry <benjurry@yeah.net>:

***STOP:0x0000001e(0X00000005,0X804B3A51,0X00000000,0X00000000)KMODE_EXCEPTION_NOT_HANDLED. ***Address 804B3A51 base at 80400000,Datastamp 384D9B17-ntoskrnl.exe


 

Privacy Statement
Copyright 2010, SecurityFocus