CVE
- Id
- 1877
- CVE No.
- CVE-2000-0299
- Status
- Candidate
- Description
- Buffer overflow in WebObjects.exe in the WebObjects Developer 4.5 package allows remote attackers to cause a denial of service via an HTTP request with long headers such as Accept.
- Phase
- Proposed (20000426)
- Votes
- ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Williams | REVIEWING(1) Levy
- Comments
- Christey> ADDREF XF:webobjects-post-dos | Frech> XF:webobjects-post-dos | Christey> See http://til.info.apple.com/techinfo.nsf/artnum/n75087 | Document says: | "A request with a large, malformed http header can crash a WOApp" | (Apple reference #2470254) appears to be the acknowledgement needed. | | Is this sufficient acknowledgement? This is dated AUgust 24, | but the initial disclosure occurred on April 4. | Christey> BID:1896