OSVDB ID: 21844

Title: ELOG Multiple Parameter Overflow DoS

Info

Disclosure

Dec 19, 2005

Discovery

Unknown

Dates

Exploit

Dec 19, 2005

Solution

Unknown

Description

A remote overflow exists in ELOG. The application fails to perform proper bounds checking resulting in a buffer overflow. With a specially crafted request containing an overly long string to the 'cmd' or 'mode' parameter, a remote attacker can cause the application to crash resulting in a loss of availability.

Classification

Location: Remote / Network Access
Attack Type: Denial of Service, Input Manipulation
Impact: Loss of Availability
Exploit: Exploit Public
OSVDB: Web Related

Solution

Currently, there are no known upgrades, patches, or workarounds available to correct this issue.

Products

Stefan Ritt

ELOG

2.6.0-beta4

References

Credit

  • Stefan Klaas - skgroundzero-security.com - GroundZero Security Research and Software Development


Direct URL: http://osvdb.org/36218