First published: Thu Dec 11 2008(Updated: )
The SSL web administration service in NetWin SmsGate 1.1n and earlier allows remote attackers to cause a denial of service (hang) via (1) a large integer in the Content-Length HTTP header; (2) an invalid value in the Content-Length HTTP header, as demonstrated by a negative integer; or (3) a missing Content-Length HTTP header.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NetWin SmsGate | =1.0r | |
NetWin SmsGate | =1.0h | |
NetWin SmsGate | <=1.1n | |
NetWin SmsGate | =1.0w | |
NetWin SmsGate | =1.1m | |
NetWin SmsGate | =1.0c | |
NetWin SmsGate | =1.0a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5421 is classified as a denial of service vulnerability that can cause the affected service to hang.
To mitigate CVE-2008-5421, upgrade to a version of NetWin SmsGate that is later than 1.1n.
CVE-2008-5421 affects all versions of NetWin SmsGate up to and including 1.1n.
Yes, CVE-2008-5421 can be exploited remotely by sending specially crafted HTTP headers to the service.
The denial of service in CVE-2008-5421 can occur due to a large or invalid integer in the Content-Length HTTP header.