First published: Sun Aug 23 1998(Updated: )
Format string vulnerability in AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via encoded % characters in an HTTP request, which is improperly logged.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Solaris Answerbook2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1417 is considered a high severity vulnerability due to its potential to cause denial of service and execute arbitrary commands.
To mitigate CVE-1999-1417, it is recommended to upgrade the AnswerBook2 web server to a patched version that addresses this vulnerability.
CVE-1999-1417 primarily affects installations of the AnswerBook2 web server (dwhttpd 3.1a4) running on Sun Solaris.
CVE-1999-1417 enables remote attackers to potentially execute arbitrary commands through crafted HTTP requests.
Implementing proper input validation and logging practices can help mitigate the risks associated with CVE-1999-1417.