PT-2016-7778 · Boa · Boa Web Server

CVE-2016-9564

·

Published

2016-11-30

·

Updated

2024-02-14

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Boa Webserver version 0.92r
Description The issue is related to a buffer overflow in the send redirect() function, which can be triggered by remote attackers through an HTTP GET request. This request must contain a long URI with only '/' and '.' characters, leading to a denial of service (DoS).
Recommendations For Boa Webserver version 0.92r, consider restricting access to the send redirect() function until a patch is available. As a temporary workaround, limit the length of URIs that can be processed by the server to prevent the buffer overflow.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-9564

Affected Products

Boa Web Server