CVE-2001-0460: Medium severity Baltimore Technologies WEBsweeper vulnerability
Published May 24, 2001
·Updated
Websweeper 4.0 does not limit the length of certain HTTP headers, which allows remote attackers to cause a denial of service (memory exhaustion) via an extremely large HTTP Referrer: header.
Affected Software
1 affected component
Baltimore Technologies WEBsweeper=4.0
Remediation
Patch Available
Event History
May 24, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0460?
CVE-2001-0460 has a severity rating that indicates it can lead to a denial of service through memory exhaustion.
2
How do I fix CVE-2001-0460?
To fix CVE-2001-0460, upgrade to a patched version of Websweeper or implement a firewall rule to limit the size of HTTP headers.
3
What type of attack does CVE-2001-0460 facilitate?
CVE-2001-0460 facilitates a denial of service attack by exploiting the lack of length limits on HTTP headers.
4
Which software is affected by CVE-2001-0460?
CVE-2001-0460 specifically affects Websweeper version 4.0 from Baltimore Technologies.
5
Is CVE-2001-0460 still a threat?
CVE-2001-0460 poses a threat primarily to outdated installations of Websweeper that have not been patched.