VID |
22389 |
Severity |
30 |
Port |
80, ... |
Protocol |
TCP |
Class |
WWW |
Detailed Description |
A version of FirstClass which is older or as old as than version 8.0 is detected as installed on the host. OpenText FirstClass is a collaborative groupware application. FirstClass version 8.0 and earlier versions are vulnerable to a denial of service attack. The vulnerability is caused due to an error in the handling of large requests. By sending a large amount of POST requests to "/Search" over multiple connections, a remote attacker could cause a vulnerable server to stop responding
* Note: This check solely relied on the banner of the remote HTTP server to assess this vulnerability, so this might be a false positive.
* References: http://archives.neohapsis.com/archives/fulldisclosure/2004-12/0321.html http://www.securitytracker.com/alerts/2004/Dec/1012478.html
* Platforms Affected: OpenText, FirstClass version 8.0 and earlier versions Apple Computer, Inc., Mac OS 10.x Microsoft Windows Any version |
Recommendation |
No upgrade or patch available as of December 2005.
Upgrade to a version of FirstClass greater than 8.0.0, when new fixed version becomes available from the OpenText FirstClass Downloads Web site at http://www.firstclass.com/Downloads/ |
Related URL |
CVE-2004-2496 (CVE) |
Related URL |
11877 (SecurityFocus) |
Related URL |
18424 (ISS) |
|