13 lines
No EOL
783 B
Text
13 lines
No EOL
783 B
Text
source: https://www.securityfocus.com/bid/278/info
|
|
|
|
A buffer overflow vulnerability in SmartDesk WebSuite 2.1 allows malicious remote users to crash the server, and may at worst allow them to execute arbitrary code.
|
|
|
|
WebSuite 2.1 will crash when the filename requested is overly long. Test showed the filename length that crashed the server varied from 250 to over 2,000 bytes long.
|
|
|
|
On Windows 98, append 150 to 1,000+ characters to the URL.
|
|
|
|
On Windows NT, append 250 to 2,000+ characters to the URL.
|
|
|
|
example:
|
|
|
|
http://hostname/00000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000 000000000000000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000000000000000000000000000000000000000 |