|
|
Info |
Last Modified |
| 8 months ago |
|
|
|
|
Description |
OmniHTTPd contains a flaw that allows a remote attacker to execute arbitrary code on a vulnerable server. The issue is due to the "imagemap.exe" program (installed by default) not sanitizing input. By passing overly long arguments to the program, the attacker can overflow a strcpy() call and execute remote code.
|
|
Classification |
Attack Type:
Input Manipulation
|
|
Solution |
Upgrade to version 2.10 or higher, as it has been reported to fix this vulnerability. It is also possible to correct the flaw by implementing the following workaround: Remove the imagemap.exe program if it is not required.
|
|
Products |
|
Web Server
 |
1.01 |
Web Server Pro
 |
2.04 |
|
|
|
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|