OmniHTTPd Pro Long POST Request DoS

medium Nessus Plugin ID 15553

Synopsis

The remote web server is vulnerable to a denial of service.

Description

The remote host is running OmniHTTPd Pro HTTP Server.

The remote version of this software seems to be vulnerable to a buffer overflow when handling specially long POST request. This may allow an attacker to crash the remote service, thus preventing it from answering legitimate client requests.

Solution

None at this time.

Plugin Details

Severity: Medium

ID: 15553

File Name: OmniHTTPd_pro_post_dos.nasl

Version: 1.12

Type: remote

Family: Web Servers

Published: 10/25/2004

Updated: 6/12/2020

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.5

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 5/15/2001

Reference Information

CVE: CVE-2001-0613

BID: 2730