Release DateJan 21, 2010 |
Severityhigh |
ImpactSystem compromise or denial of service |
DescriptionThis indicates a possible attack against a format-string vulnerability in the HTTP service of HTTPDX HTTP server.This vulnerability is due to the software's inability to properly handle specially crafted HTTP requests containing format specifiers. A remote attacker may exploit this to cause memory corruption or arbitrary code execution. |
Affected ProductsHTTPDX server 1.5 and prior versions |
Recommended ActionsCurrently we are not aware of any officially supplied patch for this issue. |
Coverage IPS
VCM |
Reference/shttp://www.vupen.com/english/advisories/2009/3312 |