CVE-2008-5421: Medium severity netwin smsgate vulnerability
The SSL web administration service in NetWin SmsGate 1.1n and earlier allows remote attackers to cause a denial of service (hang) via (1) a large integer in the Content-Length HTTP header; (2) an invalid value in the Content-Length HTTP header, as demonstrated by a negative integer; or (3) a missing Content-Length HTTP header.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5421?
CVE-2008-5421 is classified as a denial of service vulnerability that can cause the affected service to hang.
How do I fix CVE-2008-5421?
To mitigate CVE-2008-5421, upgrade to a version of NetWin SmsGate that is later than 1.1n.
What versions of NetWin SmsGate are affected by CVE-2008-5421?
CVE-2008-5421 affects all versions of NetWin SmsGate up to and including 1.1n.
Can CVE-2008-5421 be exploited remotely?
Yes, CVE-2008-5421 can be exploited remotely by sending specially crafted HTTP headers to the service.
What are the conditions that lead to the denial of service in CVE-2008-5421?
The denial of service in CVE-2008-5421 can occur due to a large or invalid integer in the Content-Length HTTP header.