Savant Webserver Buffer Overflow Vulnerability

From: Tamer Sahin (tsat_private)
Date: Sat Jan 05 2002 - 10:40:36 PST

  • Next message: rsanmcarat_private: "BOOZT! Standard 's administration cgi vulnerable to buffer overflow"

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    Savant Webserver Buffer Overflow Vulnerability
    
    Type:
    DoS, crashes Daemon
    
    Release Date:
    January 5, 2002
    
    Product / Vendor:
    Savant is a freeware open source web server that runs on Windows 95,
    98, ME, NT, and 2000, turning any desktop computer into a powerful
    web server.  Designed to be fast, secure, and efficient, Savant is
    the choice of thousands of professional and amateur webmasters
    worldwide.
    
    http://savant.sourceforge.net
    
    Summary:
    Server crashes after sending very long parameter a few times.
    
    http://host/cgi-bin/cgi-test.pl.......................................
    ......................................................................
    ......................................................................
    ...........................................................
    
    The instruction at "0x002e2e3d" referenced memory at "0xac40303c".
    The memory could not be "written".
    
    Log:
    Error File: <error.txt>
    - -
    - -
    - -
    Error: TCP buffer overflow
    Error: TCP buffer overflow
    Error: TCP buffer overflow
    Error: TCP buffer overflow
    Error: TCP buffer overflow
    Error: TCP buffer overflow
    Error: TCP buffer overflow
    Error: TCP buffer overflow
    Error: TCP buffer overflow
    Error: TCP buffer overflow
    Error: TCP buffer overflow
    Error: TCP buffer overflow
    Error: TCP buffer overflow
    Error: Failure to create CGI Process
    Error: Failure to create CGI Process
    Error: Failure to create CGI Process
    Error: Failure to create CGI Process
    Error: Failure to create CGI Process
    Error: Failure to create CGI Process
    Error: Failure to create CGI Process
    Error: Failure to create CGI Process
    Error: Failure to create CGI Process
    
    Tested:
    Windows 2000 / Savant 3.0
    
    Vulnerable:
    Savant 3.0 (And may be other)
    
    Disclaimer:
    http://www.securityoffice.net is not responsible for the misuse or
    illegal use of any of the information and/or the software listed on
    this security advisory.
    
    Author:
    Tamer Sahin
    tsat_private
    http://www.securityoffice.net
    
    Tamer Sahin
    http://www.securityoffice.net
    PGP Key ID: 0x2B5EDCB0 Fingerprint:
    B96A 5DFC E0D9 D615 8D28 7A1B BB8B A453 2B5E DCB0
    
    -----BEGIN PGP SIGNATURE-----
    Version: PGPfreeware 6.5.3 for non-commercial use <http://www.pgp.com>
    
    iQA/AwUBPDcshLuLpFMrXtywEQL0bACeM44Xr7N0zPXduVW4U1NdIFJNuiMAoKjB
    1y6tAUbi+r6NHBiJ6YzHcjTV
    =CbRI
    -----END PGP SIGNATURE-----
    



    This archive was generated by hypermail 2b30 : Sat Jan 05 2002 - 16:38:10 PST