Vulnerabilities > CVE-2009-3586 - Numeric Errors vulnerability in Frank Yaul Corehttp 0.5.3.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Off-by-one error in src/http.c in CoreHTTP 0.5.3.1 and earlier allows remote attackers to cause a denial of service or possibly execute arbitrary code via an HTTP request with a long first line that triggers a buffer overflow. NOTE: this vulnerability reportedly exists because of an incorrect fix for CVE-2007-4060.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
Exploit-Db
description | CoreHTTP web server off-by-one buffer overflow vulnerability. CVE-2009-3586. Dos exploit for linux platform |
id | EDB-ID:10349 |
last seen | 2016-02-01 |
modified | 2009-12-02 |
published | 2009-12-02 |
reporter | Patroklos Argyroudis |
source | https://www.exploit-db.com/download/10349/ |
title | CoreHTTP Web server <= 0.5.3.1 - off-by-one Buffer Overflow Vulnerability |
Packetstorm
data source | https://packetstormsecurity.com/files/download/83483/corex.py.txt |
id | PACKETSTORM:83483 |
last seen | 2016-12-05 |
published | 2009-12-07 |
reporter | Patroklos Argyroudis |
source | https://packetstormsecurity.com/files/83483/CoreHTTP-0.5.3.1-Buffer-Overflow.html |
title | CoreHTTP 0.5.3.1 Buffer Overflow |
Seebug
bulletinFamily | exploit |
description | No description provided by source. |
id | SSV:18437 |
last seen | 2017-11-19 |
modified | 2009-12-02 |
published | 2009-12-02 |
reporter | Root |
source | https://www.seebug.org/vuldb/ssvid-18437 |
title | CoreHTTP web server off-by-one buffer overflow vulnerability |
References
- http://census-labs.com/media/corex.txt
- http://census-labs.com/media/corex.txt
- http://census-labs.com/news/2009/12/02/corehttp-web-server/
- http://census-labs.com/news/2009/12/02/corehttp-web-server/
- http://www.securityfocus.com/archive/1/508272/100/0/threaded
- http://www.securityfocus.com/archive/1/508272/100/0/threaded