O’Reilly WebSite ‘webfind.exe’缓冲区溢出漏洞

漏洞信息详情

O’Reilly WebSite ‘webfind.exe’缓冲区溢出漏洞

漏洞简介

O\’\’Reilly WebSite Professional web server 2.x版本中的Webfind CGI程序存在缓冲区溢出漏洞。远程攻击者借助包含超长\”keywords\”参数的URL执行任意命令。

漏洞公告

Upgrade to at least version 2.5 of the software.
OReilly Software WebSite Professional 2.3.18

OReilly Software WebSite Professional 2.4

OReilly Software WebSite Professional 2.4.9

参考网址

来源: website.oreilly.com
链接:http://website.oreilly.com/support/software/wspro25_releasenotes.txt

来源: XF
名称: website-webfind-bo(4962)
链接:http://xforce.iss.net/static/4962.php

来源: BID
名称: 1487
链接:http://www.securityfocus.com/bid/1487

来源: NAI
名称: 20000719 O’Reilly WebSite Professional Overflow
链接:http://www.nai.com/research/covert/advisories/043.asp

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享