CVE-2004-2505: Medium severity Macromedia ColdFusion vulnerability
Published Dec 31, 2004
·Updated
Macromedia ColdFusion MX before 6.1 does not restrict the size of error messages, which allows remote attackers to cause a denial of service (memory consumption and crash) by sending repeated GET or POST requests that trigger error messages that use long strings of data.
Affected Software
2 affected components
Macromedia ColdFusion=6.0
Macromedia ColdFusion=5.0
Remediation
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Oct 25, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2505?
CVE-2004-2505 has a moderate severity as it can lead to denial of service due to excessive memory consumption.
2
How do I fix CVE-2004-2505?
To fix CVE-2004-2505, upgrade to Macromedia ColdFusion MX version 6.1 or later.
3
What software is affected by CVE-2004-2505?
CVE-2004-2505 affects Macromedia ColdFusion versions 5.0 and 6.0.
4
What type of attack is associated with CVE-2004-2505?
CVE-2004-2505 is associated with remote denial of service attacks via manipulated GET and POST requests.
5
Can CVE-2004-2505 be exploited from the internet?
Yes, CVE-2004-2505 can be exploited by remote attackers over the internet due to its lack of input validation.