CNCVE编号:CNCVE-20020046 CVE编号: 安全级别:高 漏洞中文描述: Phusion Webserver是一个商业的HTTP服务器,它运行于Microsoft Windows平台。Phusion Webserver存在一个缓冲区溢出漏洞。Phusion Webserver没有对额外提交的数据进行充分的边界检查。这使一个远程攻击者提交一个超长的web请求将会引起堆变量被攻击者提交的指令覆盖。Microsoft Windows平台上的web服务器通常以SYSTEM权限运行,这将使攻击者可以完全控制目标主机。这个缓冲区溢出问题同样能引起拒绝服务攻击。 漏洞英文描述: Phusion Webserver is a commercial HTTP server that runs on Microsoft Windows 9x/NT/2000 operating systems. Phusion Webserver does not perform sufficient bounds checking of externally supplied data. As a result, it is possible for a remote attacker to submit an excessively long web request which may cause stack variables to be overwritten with attacker-supplied instructions. As webservers normally run with SYSTEM privileges on Microsoft Windows operating systems, this may result in a full compromise of a host running the vulnerable software. It should be noted that this unchecked buffer may also be exploited to cause a denial of service condition. 漏洞参考: http://archives.neohapsis.com/archives/bugtraq/2002-02/0180.html http://www.bbshareware.com/phusion/ 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:缓冲区溢出