First published: Fri Oct 12 2001(Updated: )
Buffer overflow in Web Publisher in iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request for a long URI with (1) GETPROPERTIES, (2) GETATTRIBUTENAMES, or other methods.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
iPlanet Web Server | =4.1_sp4 | |
iPlanet Web Server | =4.1_sp5 | |
iPlanet Web Server | =4.1_sp7 | |
iPlanet Web Server | =4.1_sp6 | |
iPlanet Web Server | =4.1_sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0746 has a high severity rating due to its potential to cause denial of service and remote code execution.
To fix CVE-2001-0746, update the iPlanet Web Server to a version that is not affected by this vulnerability.
CVE-2001-0746 affects iPlanet Web Server versions 4.1 SP3 to 4.1 SP7.
Attackers can exploit CVE-2001-0746 by sending a specially crafted request that triggers a buffer overflow.
A potential workaround for CVE-2001-0746 includes restricting access to the affected iPlanet Web Server methods using a firewall.