积极预防 及时发现
快速响应 力保恢复
Websweeper 4.0没有限制某些HTTP报头的长度,这允许远程攻击者通过极大的HTTP 回应...
发布时间:2001-06-27 信息来源:管理员

CNCVE编号:CNCVE-20010460 CVE编号:CAN-2001-0460 安全级别:高 漏洞中文描述: Websweeper 4.0没有限制某些HTTP报头的长度,这允许远程攻击者通过极大的HTTP 回应头来引发拒绝服务(内存耗尽)。 漏洞英文描述: Websweeper 4.0 does not limit the length of certain HTTP headers, which allows remote attackers to cause a denial of service (memory exhaustion) via an extremely large HTTP Referrer: header. 漏洞参考: Reference: BUGTRAQ:20010308 def-2001-10: Websweeper Infinite HTTP Request DoS Reference: URL:http://www.securityfocus.com/archive/1/167406 Reference: XF:websweeper-http-dos Reference: URL:http://xforce.iss.net/static/6214.php 系统类型: Win2000/NT 漏洞类型:输入有效性检查错误