Update Protection against openwsman HTTP Basic Authentication Buffer Overflow
| Check Point Reference: | CPAI-2008-235 | |
| Date Published: | ||
| Severity: | ||
| Source: | Secunia Advisory: SA31410 | |
| Industry Reference(s): | CVE-2008-2234 | |
| Protection Provided by: |
IPS-1
|
|
| Who is Vulnerable? openwsman 1.x openwsman 2.x | ||
| Vulnerability Description A buffer overflow vulnerability was reported in Openwsman. Openwsman is an implementation of Web Services Management (WS-Management) specification. It is used in the VMware Management ServiceConsole. The vulnerability is due to improper bounds checking of HTTP authorization headers. Remote unauthenticated attackers could exploit this vulnerability by sending HTTP requests with overly long header values. Successful exploitation would result in execution of arbitrary code or a denial of service condition. |
||
|
Vulnerability Status The vulnerability has been publicly disclosed. |
|
|
Vulnerability Details In order for a remote attack to be successful, the attacker needs to have access to the service console network. |
Protection Overview
By enabling this protection, IPS-1 will detect and block CGI requests with invalid HTTP Authentication header lengths.
To configure the defense, select your product from the list below and follow the related protection steps.