Buffer overflows in forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 up to and including 4.2.1 allows remote malicious users to execute arbitrary code via long arguments to the parameters (1) Mode, (2) Certificate_File, (3) useExpiredCRLs, (4) listenLength, (5) maxThread, (6) maxConnPerSite, (7) maxMsgLen, (8) exitTime, (9) blockTime, (10) nextUpdatePeriod, (11) buildLocal, (12) maxOCSPValidityPeriod, (13) extension, and (14) a particular combination of parameters associated with private key generation that form a string of a certain length.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
valicert enterprise validation authority 3.3 |
||
valicert enterprise validation authority 3.4 |
||
valicert enterprise validation authority 4.1 |
||
valicert enterprise validation authority 4.2 |
||
valicert enterprise validation authority 3.5 |
||
valicert enterprise validation authority 3.6 |
||
valicert enterprise validation authority 4.2.1 |
||
valicert enterprise validation authority 3.9 |
||
valicert enterprise validation authority 4.0 |
||
valicert enterprise validation authority 3.7 |
||
valicert enterprise validation authority 3.8 |