xfocus logo xfocus title
首页 焦点原创 安全文摘 安全工具 安全漏洞 焦点项目 焦点论坛 关于我们
English Version

WN Server不正规GET请求可导致缓冲溢出


发布时间:2002-10-08
更新时间:2002-10-08
严重程度:
威胁程度:远程拒绝服务
错误类型:边界检查错误
利用方式:服务器模式

BUGTRAQ ID:5831
CVE(CAN) ID:CAN-2002-1166

受影响系统
WN Server WN Server 1.18.2
WN Server WN Server 1.18.3
WN Server WN Server 1.18.4
WN Server WN Server 1.18.5
WN Server WN Server 1.18.6
WN Server WN Server 1.18.7
WN Server WN Server 1.19 .0
WN Server WN Server 1.19.1
WN Server WN Server 1.19.2
WN Server WN Server 1.19.3
WN Server WN Server 1.19.4
WN Server WN Server 1.19.5
WN Server WN Server 1.19.6
WN Server WN Server 1.19.7
WN Server WN Server 1.19.8
WN Server WN Server 1.19.9
WN Server WN Server 2.0 .0
详细描述
WN是可运行在多种系统平台下的WEB服务程序。

由于对HTTP GET请求数据缺少正确检查,攻击者发送超长请求给服务器,可导致内存破坏,以WEB服务程序的权限执行任意代码。

测试代码


解决方案
升级程序:

WN Server WN Server 1.18.2:

WN Server Upgrade wn-2.4.4.tar.gz
http://hopf.math.nwu.edu/wn-2.4.4.tar.gz

WN Server WN Server 1.18.3:

WN Server Upgrade wn-2.4.4.tar.gz
http://hopf.math.nwu.edu/wn-2.4.4.tar.gz

WN Server WN Server 1.18.4:

WN Server Upgrade wn-2.4.4.tar.gz
http://hopf.math.nwu.edu/wn-2.4.4.tar.gz

WN Server WN Server 1.18.5:

WN Server Upgrade wn-2.4.4.tar.gz
http://hopf.math.nwu.edu/wn-2.4.4.tar.gz

WN Server WN Server 1.18.6:

WN Server Upgrade wn-2.4.4.tar.gz
http://hopf.math.nwu.edu/wn-2.4.4.tar.gz

WN Server WN Server 1.18.7:

WN Server Upgrade wn-2.4.4.tar.gz
http://hopf.math.nwu.edu/wn-2.4.4.tar.gz

WN Server WN Server 1.19 .0:

WN Server Upgrade wn-2.4.4.tar.gz
http://hopf.math.nwu.edu/wn-2.4.4.tar.gz

WN Server WN Server 1.19.1:

WN Server Upgrade wn-2.4.4.tar.gz
http://hopf.math.nwu.edu/wn-2.4.4.tar.gz

WN Server WN Server 1.19.2:

WN Server Upgrade wn-2.4.4.tar.gz
http://hopf.math.nwu.edu/wn-2.4.4.tar.gz

WN Server WN Server 1.19.3:

WN Server Upgrade wn-2.4.4.tar.gz
http://hopf.math.nwu.edu/wn-2.4.4.tar.gz

WN Server WN Server 1.19.4:

WN Server Upgrade wn-2.4.4.tar.gz
http://hopf.math.nwu.edu/wn-2.4.4.tar.gz

WN Server WN Server 1.19.5:

WN Server Upgrade wn-2.4.4.tar.gz
http://hopf.math.nwu.edu/wn-2.4.4.tar.gz

WN Server WN Server 1.19.6:

WN Server Upgrade wn-2.4.4.tar.gz
http://hopf.math.nwu.edu/wn-2.4.4.tar.gz

WN Server WN Server 1.19.7:

WN Server Upgrade wn-2.4.4.tar.gz
http://hopf.math.nwu.edu/wn-2.4.4.tar.gz

WN Server WN Server 1.19.8:

WN Server Upgrade wn-2.4.4.tar.gz
http://hopf.math.nwu.edu/wn-2.4.4.tar.gz

WN Server WN Server 1.19.9:

WN Server Upgrade wn-2.4.4.tar.gz
http://hopf.math.nwu.edu/wn-2.4.4.tar.gz

WN Server WN Server 2.0 .0:

WN Server Upgrade wn-2.4.4.tar.gz
http://hopf.math.nwu.edu/wn-2.4.4.tar.gz

相关信息
badc0ded <badc0ded@badc0ded.com>.
参考:http://online.securityfocus.com/archive/1/293542
相关主页:http://hopf.math.nwu.edu/