20030731 Sending 2GB Data in GET Request Causes Buffer Overflow in Cisco IOS SoftwareVendor advisory
http://www.cisco.com/warp/public/707/cisco-sn-20030730-ios-2gb-get.shtml CVE-2003-0647
Cisco IOS 12.x/11.x - HTTP Remote Integer Overflow
Record summary
CVE-2003-0647 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Buffer overflow in the HTTP server for Cisco IOS 12.2 and earlier allows remote attackers to execute arbitrary code via an extremely long (2GB) HTTP GET request.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCisco IOS 12.x/11.x - HTTP Remote Integer OverflowExploitDB exploitby FXNot analyzed1 file
References
3VU#579324Third-party advisory
http://www.kb.cert.org/vuls/id/579324 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2003-0647