Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Xitami Webserver MS-DOS Device Name DoS Vulnerability

Solution:
In a followup advisory dated April 18, 2001, the vendor notes:
---
we plan to release a minor update to both Xitami 2.4 (release code), and Xitami 2.5 (beta test code)
with a work around for this issue, possibly including a hard coded check for AUX that is always done, in addition to the Win32 QueryDosDevice() where available. This update will be announced on the Xitami user mailing list, and announcement list when it is available.

Meanwhile some Xitami users have reported that defining an Xitami alias for "AUX" that points at some non-existant file avoids the issue reported (as the alias expansion is done before any files are opened); we would suggest those looking for an immediate work around consider this.
---


Imatix Xitami for Windows 2.4 d7

Imatix Xitami for Windows 2.5 b4







 

Privacy Statement
Copyright 2008, SecurityFocus