HTTP.Server.Authorization.Buffer.Overflow

description-logoDescription

This indicates detection of an overly long HTTP Authorization value.
HTTP servers that have insufficient sanitizing of HTTP requests field might be prone to such an attack. Successful attacks may allow a remote attacker to execute arbitrary code within the context of the webserver, crash the affected application or deny services to legitimate users.

affected-products-logoAffected Products

Any unprotected or misconfigured HTTP server is vulnerable to the attack.

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply appropriate patches or upgrade the system to the latest non-vulnerable version.
Monitor the traffic from that network for any suspicious activity.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2021-01-13 16.997 Sig Added
2020-06-08 15.859 Default_action:pass:drop
2020-05-26 15.851 Sig Added

References

44356