CVE-2009-4873

high

Description

Stack-based buffer overflow in the HTTP server in Rhino Software Serv-U Web Client 9.0.0.5 allows remote attackers to cause a denial of service (server crash) or execute arbitrary code via a long Session cookie.

References

http://secunia.com/advisories/37228

http://www.rangos.de/ServU-ADV.txt

http://www.securityfocus.com/bid/36895

http://www.vupen.com/english/advisories/2009/3116

Details

Source: MITRE

Published: 2010-05-26

Updated: 2010-05-26

Type: CWE-119

Risk Information

CVSS v2

Base Score: 10

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 10

Severity: HIGH