CVE
- Id
- 2051
- CVE No.
- CVE-2000-0473
- Status
- Candidate
- Description
- Buffer overflow in AnalogX SimpleServer 1.05 allows a remote attacker to cause a denial of service via a long GET request for a program in the cgi-bin directory.
- Phase
- Proposed (20000712)
- Votes
- ACCEPT(1) Levy | MODIFY(1) Frech | REVIEWING(1) Christey
- Comments
- Christey> Appears to be the same as, or similar to, CVE-2000-0011, which was | also discovered by USSR. Comments on the AnalogX web site are | decidedly sparse. In CVE-2000-0011, USSR only claims that | the vendor was informed, so is this still the same problem? | | XF:simpleserver-long-url-dos | Frech> XF:simpleserver-long-url-dos(4693) | Please review whether your BUGTRAQ:19991231 reference is correct; seems like | this is the reference to CVE-2000-0011: Buffer overflow in AnalogX | SimpleServer:WWW HTTP server allows remote attackers to execute commands via | a long GET request. They are subtle; almost the only thing that changed was | the version. | A possible reference is "Remote DoS attack in AnalogX SimpleServer WWW | Version 1.05 Vulnerability" at http://www.ussrback.com/labs45.html.