PT-2002-2538 · Atp · Atophttpd

CVE-2002-1816

·

Publicado

2002-12-31

·

Atualizado

2025-01-16

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ATPhttpd versions 0.4b and earlier
Description The issue is an off-by-one buffer overflow in the sock gets function in sockhelp.c, which allows remote attackers to execute arbitrary code via a long HTTP GET request.
Recommendations For ATPhttpd versions 0.4b and earlier, consider disabling the sock gets function in sockhelp.c to prevent exploitation until a patch is available. Restrict access to the ATPhttpd service to minimize the risk of exploitation. Avoid using long HTTP GET requests in the affected ATPhttpd versions until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2002-1816

Produtos afetados

Atophttpd