| VID |
22332 |
| Severity |
40 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
WWW |
| Detailed Description |
The BadBlue server, according to its banner, has a buffer overflow vulnerability in the 'ext.dll'. BadBlue is a P2P file sharing Web server distributed by Working Resources for Microsoft Windows operating systems. BadBlue versions 2.55 and earlier are vulnerable to a buffer overflow vulnerability in the 'mfcisapicommand' parameter in the 'ext.dll'. A remote attacker could exploit this vulnerability by sending an http request containing a mfcisapicommand parameter with more than 250 characters to kill the web server and possibly execute code remotely.
* Note: This check solely relied on the banner of the remote HTTP server to assess this vulnerability, so this might be a false positive.
* References: http://www.securitytracker.com/alerts/2005/Feb/1013308.html http://www.osvdb.org/displayvuln.php?osvdb_id=12673
* Platforms Affected: Working Resources Inc., BadBlue Enterprise Edition 2.55 and earlier Working Resources Inc., BadBlue Personal Edition 2.55 and earlier Microsoft Windows Any version |
| Recommendation |
Upgrade to the latest version of BadBlue (2.61 or later), available from the BadBlue Download Web site at http://www.badblue.com/down.htm |
| Related URL |
CVE-2005-0595 (CVE) |
| Related URL |
12673 (SecurityFocus) |
| Related URL |
19496 (ISS) |
|