Vulnerabilities > CVE-2002-1816 - Off-by-one Error vulnerability in Redshift Atphttpd 0.4B

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
redshift
CWE-193
critical
exploit available

Summary

Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.

Vulnerable Configurations

Part Description Count
Application
Redshift
2

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionATP httpd 0.4 Single Byte Buffer Overflow Vulnerability. CVE-2002-1816. Remote exploit for linux platform
idEDB-ID:21936
last seen2016-02-02
modified2002-10-05
published2002-10-05
reporterthread
sourcehttps://www.exploit-db.com/download/21936/
titleATP httpd 0.4 Single Byte Buffer Overflow Vulnerability