Abyss Web Server Malformed GET Request Remote DoS

medium Nessus Plugin ID 11521

Language:

Synopsis

The remote web server is vulnerable to a denial of service attack.

Description

It was possible to kill the remote web server by sending empty HTTP request headers (namely Connection: or Range:).

An attacker may use this flaw to crash the affected application, thereby denying service to legitimate users.

Solution

Upgrade to version 1.1.4 or higher, as it has been reported to fix this vulnerability.

See Also

https://seclists.org/bugtraq/2003/Apr/98

Plugin Details

Severity: Medium

ID: 11521

File Name: abyss_dos.nasl

Version: 1.22

Type: remote

Family: Web Servers

Published: 4/6/2003

Updated: 11/15/2018

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.0

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Information

Required KB Items: www/abyss

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 4/6/2003

Reference Information

CVE: CVE-2003-1364

BID: 7287

CWE: 20

Secunia: 8528