Vulnerability Scanning Solutions, LLC.
Home
Our Process
Residential
Corporate
What We Scan For
Sample Report
Client List
Terms
Contact Us
What We Scan For
Family: CGI abuses --> Category: attack

Sympa wwsympa do_search_list Overflow DoS Vulnerability Scan


Vulnerability Scan Summary
Checks for sympa version

Detailed Explanation for this Vulnerability Test

The remote host is running SYMPA, an open source mailing list software.

This version of Sympa has a flaw in one of it's scripts (wwsympa.pl) which
would allow a remote attacker to overflow the sympa server. Specifically,
within the cgi script wwsympa.pl is a do_search_list function which fails to perform
bounds checking. A possible hacker, passing a specially formatted long string
to this function, would be able to crash the remote sympa server. At the
time of this writing, the attack is only known to cause a Denial of Service
(DoS).

Solution : Update to version 4.1.2 or newer

See also: http://www.sympa.org/

Threat Level: Medium

Click HERE for more information and discussions on this network vulnerability scan.

VSS, LLC.

P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.