20020922 remote exploitable heap overflow in Null HTTPd 0.5.0mailing list
http://archives.neohapsis.com/archives/bugtraq/2002-09/0284.html CVE-2002-1496
Null HTTPd 0.5 - Remote Heap Overflow
Record summary
CVE-2002-1496 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Heap-based buffer overflow in Null HTTP Server 0.5.0 and earlier allows remote attackers to execute arbitrary code via a negative value in the Content-Length HTTP header.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBNull HTTPd 0.5 - Remote Heap OverflowExploitDB exploitby eSDeeNot analyzed1 file
References
5freshmeat.netConfirmation
http://freshmeat.net/releases/97910 null-httpd-contentlength-bo(10160)vdb entry
http://www.iss.net/security_center/static/10160.php 5774vdb entry
http://www.securityfocus.com/bid/5774 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-1496