CVE-1999-1535: Buffer Overflow
Buffer overflow in AspUpload.dll in Persits Software AspUpload before 1.4.0.2 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument in the HTTP request.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Persits AspUploadto a version that resolves this vulnerability.Fixed in 1.4.0.2 - Compensating control
Use a web application firewall or reverse proxy to block or limit overly long HTTP request arguments (enforce maximum parameter/argument length) and/or restrict access to AspUpload endpoints to trusted IPs until the component is updated to 1.4.0.2.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1535?
CVE-1999-1535 is classified as a remote code execution vulnerability that can lead to a denial of service.
How do I fix CVE-1999-1535?
To fix CVE-1999-1535, upgrade to AspUpload version 1.4.0.2 or later.
What causes CVE-1999-1535?
CVE-1999-1535 is caused by a buffer overflow in AspUpload.dll when handling long arguments in HTTP requests.
What are the potential impacts of CVE-1999-1535?
The potential impacts of CVE-1999-1535 include denial of service and the ability for attackers to execute arbitrary commands.
Which software versions are affected by CVE-1999-1535?
CVE-1999-1535 affects all versions of Persits Software AspUpload prior to 1.4.0.2.