giFT-FastTrack daemon denial of service
| gift-fasttrack-daemon-dos (16508) |
Description:
giFT-FastTrack is vulnerable to a denial of service attack. A remote attacker could cause a NULL pointer dereference and cause the daemon to crash.
Consequences:
Denial of Service
Remedy:
Upgrade to the latest version of giFT-FastTrack (0.8.7 or later), available from the giFT-FastTrack Web site. See References.
For Gentoo Linux:
Upgrade to the latest version of giFT-FastTrack (0.8.7 or later), as listed in GLSA 200406-19. See References.
For other distributions:
Contact your vendor for upgrade or patch information.
References:
- giFT-FastTrack Web site: giFT-FastTrack.
- GLSA 200406-19: giFT-FastTrack: remote denial of service attack.
- BID-10604: giFT-FastTrack HTTP Header Parser Remote Denial Of Service Vulnerability
- CVE-2004-0604: The HTTP client and server in giFT-FastTrack 0.8.6 and earlier allows remote attackers to cause a denial of service (crash), possibly via an empty search query, which triggers a NULL dereference.
- GLSA-200406-19: giFT-FastTrack: remote denial of service attack
- SA11941: giFT-FastTrack Unspecified Denial of Service Vulnerability
Platforms Affected:
- berliOS giFT-FastTrack 0.8.6 and prior
- Gentoo Linux
Reported:
Jun 25, 2004
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
