7.5
CVSSv2

CVE-2002-2295

Published: 31/12/2002 Updated: 29/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in Pico Server (pServ) 2.0 beta 1 through beta 5 allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via (1) a 1024-byte TCP stream message, which triggers an off-by-one buffer overflow, or (2) a long method name in an HTTP request, (3) a long version number in an HTTP request, (4) a long User-Agent header, or (5) a long file path.

Vulnerable Product Search on Vulmon Subscribe to Product

pico server pico server 2.0_beta_1

pico server pico server 2.0_beta_2

pico server pico server 2.0_beta_3

pico server pico server 2.0_beta_5

Exploits

source: wwwsecurityfocuscom/bid/6285/info A buffer overflow vulnerability has been reported in Pserv The buffer overflow condition is due to the way Pserv handles data streams from remote connections An attacker can exploit this vulnerability by issuing a HTTP request with an invalid HTTP version specifier Due to insufficient buffers ...