Abyss Web Server Malformed GET Request Remote DoS
|
|
Article ID: 11521
Last updated: 27 Jan, 2009
|
|
|
|
Views: 458
|
|
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.
|
|
Abyss Web Server Malformed GET Request Remote DoS |
|
| This script is Copyright (C) 2003-2008 Tenable Network Security, Inc. |
|
|
| Family | Denial of Service |
| Plugin ID | 11521 |
| Bugtraq ID | 7287
|
| CVE ID | CVE-2003-1364
|
|
| Description: |
It was possible to kill the web server by
sending empty HTTP fields (namely Connection: and Range: ).
An attacker may use this flaw to prevent this host from performing
its job properly.
Solution : If the remote web server is Abyss X1, then upgrade to
Abyss X1 v.1.1.4, otherwise inform your vendor of this flaw.
Risk factor : High |
|