Savant Web Server is vulnerable to remote DoS attack (GET NULL)
28 Dec. 1999
Summary
Savant Web Server provides support for most modern web features and technologies, including:
- Common Gateway Interface (CGI) 1.0 and 1.1
- HTTP 0.9, 1.0, and 1.1 including keep-alive ability
- Comprehensive logging in the standard NCSA format
- User and group management
- Password protection
- Server-side image maps
- Support for over 40 file types, including MP3, RealAudio, and Microsoft Office files
- XML, JavaScript, Java, and ActiveX, and more.
UssrLabs found a Local / Remote Buffer overflow in this product. The buffer overflow is caused when a NULL Character is inserted into the parsing GET command routine.
Credit:
The information as provided by: Ussr Labs.