Korean
<< Back
VID 12069
Severity 30
Port 80, ...
Protocol TCP
Class WWW
Detailed Description The Abyss Web Server is vulnerable to a denial of service attack via the MS-DOS device name request. Abyss Web Server is a free personal Web server developed by Aprelium Technologies for Microsoft Windows, MacOS X, Linux, and FreeBSD. Abyss Web Server X1 for Microsoft Windows is vulnerable to a denial of service attack. By sending an HTTP request for a URL containing a MS-DOS device name (con, prn, aux, etc.) in the /cgi-bin directory, a remote attacker could cause the affected Web server to crash.

* References:
http://www.osvdb.org/displayvuln.php?osvdb_id=11006
http://archives.neohapsis.com/archives/vulnwatch/2004-q4/0014.html

* Platforms Affected:
Aprelium Technologies, Abyss Web Server X1 versions prior to 1.2.3.0
Microsoft Windows Any version
Recommendation Upgrade to the latest version of Abyss Web Server X1 (1.2.3.0 or later), available from the Abyss Web Server X1 Download Web page at http://www.aprelium.com/abyssws/download.php
Related URL (CVE)
Related URL (SecurityFocus)
Related URL 17795 (ISS)