Summary
This host is running Xitami Web Server and is prone to buffer overflow vulnerability.
Impact
Successful exploitation will let the remote unauthenticated attackers to execute arbitrary code on the system or cause the application to crash.
Impact Level: System/Application
Solution
No solution or patch was made available for at least one year since disclosure of this vulnerability. Likely none will be provided anymore.
General solution options are to upgrade to a newer release, disable respective features, remove the product or replace the product by another one.
Insight
The flaw is caused the way xitami web server handles 'If-Modified-Since' header. which can be exploited to cause a buffer overflow by sending a specially-crafted parameter to 'If-Modified-Since' header.
Affected
iMatix Xitami Web Server Version 2.5c2 and 2.5b4, Other versions may also be affected.
References
Severity
Classification
-
CVE CVE-2007-5067 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- Easy RM to MP3 Converter Buffer Overflow Vulnerability
- Active Perl Modules Multiple Vulnerabilities (Windows)
- Adobe Flash Player/Air Multiple DoS Vulnerabilities - Aug09 (Win)
- 7T Interactive Graphical SCADA System 'dc.exe' Command Injection Vulnerability
- Adobe Flash Player/Air Multiple Vulnerabilities - August10 (Linux)