WN Server不正规GET请求可导致缓冲溢出发布时间:2002-10-08 更新时间:2002-10-08 严重程度:中 威胁程度:远程拒绝服务 错误类型:边界检查错误 利用方式:服务器模式 BUGTRAQ ID:5831 CVE(CAN) ID:CAN-2002-1166 受影响系统 WN Server WN Server 1.18.2详细描述 WN是可运行在多种系统平台下的WEB服务程序。 由于对HTTP GET请求数据缺少正确检查,攻击者发送超长请求给服务器,可导致内存破坏,以WEB服务程序的权限执行任意代码。 测试代码 无 解决方案 升级程序: WN Server WN Server 1.18.2: WN Server Upgrade wn-2.4.4.tar.gz http://hopf.math.nwu.edu/wn-2.4.4.tar.gz WN Server WN Server 1.18.3: WN Server Upgrade wn-2.4.4.tar.gz http://hopf.math.nwu.edu/wn-2.4.4.tar.gz WN Server WN Server 1.18.4: WN Server Upgrade wn-2.4.4.tar.gz http://hopf.math.nwu.edu/wn-2.4.4.tar.gz WN Server WN Server 1.18.5: WN Server Upgrade wn-2.4.4.tar.gz http://hopf.math.nwu.edu/wn-2.4.4.tar.gz WN Server WN Server 1.18.6: WN Server Upgrade wn-2.4.4.tar.gz http://hopf.math.nwu.edu/wn-2.4.4.tar.gz WN Server WN Server 1.18.7: WN Server Upgrade wn-2.4.4.tar.gz http://hopf.math.nwu.edu/wn-2.4.4.tar.gz WN Server WN Server 1.19 .0: WN Server Upgrade wn-2.4.4.tar.gz http://hopf.math.nwu.edu/wn-2.4.4.tar.gz WN Server WN Server 1.19.1: WN Server Upgrade wn-2.4.4.tar.gz http://hopf.math.nwu.edu/wn-2.4.4.tar.gz WN Server WN Server 1.19.2: WN Server Upgrade wn-2.4.4.tar.gz http://hopf.math.nwu.edu/wn-2.4.4.tar.gz WN Server WN Server 1.19.3: WN Server Upgrade wn-2.4.4.tar.gz http://hopf.math.nwu.edu/wn-2.4.4.tar.gz WN Server WN Server 1.19.4: WN Server Upgrade wn-2.4.4.tar.gz http://hopf.math.nwu.edu/wn-2.4.4.tar.gz WN Server WN Server 1.19.5: WN Server Upgrade wn-2.4.4.tar.gz http://hopf.math.nwu.edu/wn-2.4.4.tar.gz WN Server WN Server 1.19.6: WN Server Upgrade wn-2.4.4.tar.gz http://hopf.math.nwu.edu/wn-2.4.4.tar.gz WN Server WN Server 1.19.7: WN Server Upgrade wn-2.4.4.tar.gz http://hopf.math.nwu.edu/wn-2.4.4.tar.gz WN Server WN Server 1.19.8: WN Server Upgrade wn-2.4.4.tar.gz http://hopf.math.nwu.edu/wn-2.4.4.tar.gz WN Server WN Server 1.19.9: WN Server Upgrade wn-2.4.4.tar.gz http://hopf.math.nwu.edu/wn-2.4.4.tar.gz WN Server WN Server 2.0 .0: WN Server Upgrade wn-2.4.4.tar.gz http://hopf.math.nwu.edu/wn-2.4.4.tar.gz 相关信息 badc0ded <badc0ded@badc0ded.com>. 参考:http://online.securityfocus.com/archive/1/293542 相关主页:http://hopf.math.nwu.edu/ |