CVE-2002-2429: Input Validation
Published Feb 6, 2009
·Updated
webs.c in GoAhead WebServer before 2.1.4 allows remote attackers to cause a denial of service (daemon crash) via an HTTP POST request that contains a negative integer in the Content-Length header.
Affected Software
5 affected components
GoAhead GoAhead Webserver<=2.1.3
GoAhead GoAhead Webserver=2.0
GoAhead GoAhead Webserver=2.1
GoAhead GoAhead Webserver=2.1.1
GoAhead GoAhead Webserver=2.1.2
Event History
Feb 6, 2009
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-2429?
CVE-2002-2429 has been classified as a moderate severity vulnerability due to its ability to cause a denial of service.
2
How do I fix CVE-2002-2429?
To fix CVE-2002-2429, upgrade to GoAhead WebServer version 2.1.4 or later.
3
What types of attacks exploit CVE-2002-2429?
CVE-2002-2429 can be exploited through specially crafted HTTP POST requests with negative integers in the Content-Length header.
4
Which versions of GoAhead WebServer are affected by CVE-2002-2429?
CVE-2002-2429 affects GoAhead WebServer versions up to and including 2.1.3.
5
What impact does CVE-2002-2429 have on the GoAhead WebServer?
The impact of CVE-2002-2429 is that it can lead to the daemon crashing, resulting in a denial of service.