Vector: | Remote |
Severity: | High |
Patch: | Patched |
Impact: |
Denial of Service (DoS) Remote Code Execution (RCE) |
Software: |
Debian GNU/Linux 3.0 webfs 1.x |
A remote code execution vulnerability has been discovered in webfs Request-URI.
Buffer overflow vulnerability exists in the handling of Request-URI. An attacker can cause a buffer overflow by sending an overly long, specially crafted HTTP request.
Solution:
For Debian GNU/Linux 3.0: The vulnerability has been fixed in webfs version 1.18 and later. The latest version may be downloaded at:
CVE ID:
CVE-2003-0445
Links:
http://www.debian.org/security/2003/dsa-328