|
Phusion Webserver Long URL Buffer Overflow Vulnerability
Phusion Webserver is a commercial HTTP server that runs on Microsoft Windows 9x/NT/2000 operating systems. Phusion Webserver does not perform sufficient bounds checking of externally supplied data. As a result, it is possible for a remote attacker to submit an excessively long web request which may cause stack variables to be overwritten with attacker-supplied instructions. As webservers normally run with SYSTEM privileges on Microsoft Windows operating systems, this may result in a full compromise of a host running the vulnerable software. It should be noted that this unchecked buffer may also be exploited to cause a denial of service condition. |
|
|
Privacy Statement |