Korean
<< Back
VID 22332
Severity 40
Port 80, ...
Protocol TCP
Class WWW
Detailed Description The BadBlue server, according to its banner, has a buffer overflow vulnerability in the 'ext.dll'. BadBlue is a P2P file sharing Web server distributed by Working Resources for Microsoft Windows operating systems. BadBlue versions 2.55 and earlier are vulnerable to a buffer overflow vulnerability in the 'mfcisapicommand' parameter in the 'ext.dll'. A remote attacker could exploit this vulnerability by sending an http request containing a mfcisapicommand parameter with more than 250 characters to kill the web server and possibly execute code remotely.

* Note: This check solely relied on the banner of the remote HTTP server to assess this vulnerability, so this might be a false positive.

* References:
http://www.securitytracker.com/alerts/2005/Feb/1013308.html
http://www.osvdb.org/displayvuln.php?osvdb_id=12673

* Platforms Affected:
Working Resources Inc., BadBlue Enterprise Edition 2.55 and earlier
Working Resources Inc., BadBlue Personal Edition 2.55 and earlier
Microsoft Windows Any version
Recommendation Upgrade to the latest version of BadBlue (2.61 or later), available from the BadBlue Download Web site at http://www.badblue.com/down.htm
Related URL CVE-2005-0595 (CVE)
Related URL 12673 (SecurityFocus)
Related URL 19496 (ISS)