First published: Thu May 24 2001(Updated: )
Websweeper 4.0 does not limit the length of certain HTTP headers, which allows remote attackers to cause a denial of service (memory exhaustion) via an extremely large HTTP Referrer: header.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Baltimore Technologies WEBsweeper | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0460 has a severity rating that indicates it can lead to a denial of service through memory exhaustion.
To fix CVE-2001-0460, upgrade to a patched version of Websweeper or implement a firewall rule to limit the size of HTTP headers.
CVE-2001-0460 facilitates a denial of service attack by exploiting the lack of length limits on HTTP headers.
CVE-2001-0460 specifically affects Websweeper version 4.0 from Baltimore Technologies.
CVE-2001-0460 poses a threat primarily to outdated installations of Websweeper that have not been patched.