Openwsman_HTTP_Basic_Authentication_Buffer_Overflow_attack

Strike ID:
G08-4q201
CVSS:
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
False Positive:
t
Variants:
1
Year:
2008

Description

This strike exploits a buffer overflow vulnerability in Openwsman. The vulnerability is due to improper processing of the HTTP basic authentication header. Remote attackers could exploit this vulnerability by sending HTTP requests with specially crafted header value. Successful exploitation would allow for arbitrary code injection and execution with the privileges of the security context of the current server process. In an attack case where code injection is not successful, the affected service can terminate abnormally.

CVE

References

Bid