DiGi WWW Server 1 - Remote Denial of Service



EKU-ID: 29486 CVE: CVE-2004-1973;OSVDB-5702 OSVDB-ID:
Author: Donato Ferrante Published: 2004-04-27 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/10228/info

The DiGi WWW Server has been reported to contain a remote denial of service vulnerability. It has been reported that when the server receives a malformed HTTP GET request, the web server process will consume large amounts of CPU resources.

Since this is a web server application, this leads to a remotely exploitable denial of service vulnerability.

GET ///[660Kb of /]/// HTTP/1.1

to a vulnerable server would demonstrate the effect.