7.5
CVSSv2

CVE-2002-1496

Published: 02/04/2003 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in Null HTTP Server 0.5.0 and previous versions allows remote malicious users to execute arbitrary code via a negative value in the Content-Length HTTP header.

Vulnerable Product Search on Vulmon Subscribe to Product

nulllogic null httpd

Exploits

source: wwwsecurityfocuscom/bid/5774/info Null httpd is a small multithreaded web server for Linux and Windows, mantained by NullLogic A remotely exploitable heap overflow has been discovered in Null httpd By passing a negative content length value to the server, it is possible to modify the allocation size of the read buffer, resultin ...