| Name | Now.SMS.Gateway.Web.Authorization.Buffer.Overflow |
| Last Updated Date | Sep 23, 2008 |
| Release Date | Sep 05, 2008 |
| Severity | High |
| Impact | System Compromise: Remote attackers can gain control of vulnerable systems. |
| Description | This indicates an attempt to exploit a buffer-overflow vulnerability in the Now SMS MMS Gateway web interface.
The vulnerability is caused by a boundary error when the vulnerable software handles a long Authorization header. It allows a remote attacker to execute arbitrary code via sending a crafted HTTP request. |
| Affected Products | Now SMS/MMS Gateway 2007.06.26 and earlier. |
| Recommended Actions | Update to version 2008.02.22 or higher, available from the following web site. http://www.nowsms.com/downloads/ |
| Common Vulnerabilities and Exposures (CVE) | http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0871
|