CVE-2008-1366: Input Validation
Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patch 3 build 1314 and earlier, allows remote attackers to cause a denial of service (process consumption) via (1) an HTTP request without a Content-Length header or (2) invalid characters in unspecified CGI arguments, which triggers a NULL pointer dereference.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1366?
CVE-2008-1366 has been rated as a high severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2008-1366?
To fix CVE-2008-1366, you should update Trend Micro OfficeScan Corporate Edition to the latest version that is not affected.
What types of systems are affected by CVE-2008-1366?
CVE-2008-1366 affects Trend Micro OfficeScan Corporate Edition versions 7.3 Patch 3 build 1314 and earlier, and 8.0 Patch 2 build 1189 and earlier.
What kind of attacks does CVE-2008-1366 allow?
CVE-2008-1366 allows remote attackers to perform denial of service attacks leading to process consumption.
What are the vector types for CVE-2008-1366?
CVE-2008-1366 can be exploited through HTTP requests without a Content-Length header or via invalid characters in unspecified CGI arguments.