-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Savant Webserver Buffer Overflow Vulnerability Type: DoS, crashes Daemon Release Date: January 5, 2002 Product / Vendor: Savant is a freeware open source web server that runs on Windows 95, 98, ME, NT, and 2000, turning any desktop computer into a powerful web server. Designed to be fast, secure, and efficient, Savant is the choice of thousands of professional and amateur webmasters worldwide. http://savant.sourceforge.net Summary: Server crashes after sending very long parameter a few times. http://host/cgi-bin/cgi-test.pl....................................... ...................................................................... ...................................................................... ........................................................... The instruction at "0x002e2e3d" referenced memory at "0xac40303c". The memory could not be "written". Log: Error File: - - - - - - Error: TCP buffer overflow Error: TCP buffer overflow Error: TCP buffer overflow Error: TCP buffer overflow Error: TCP buffer overflow Error: TCP buffer overflow Error: TCP buffer overflow Error: TCP buffer overflow Error: TCP buffer overflow Error: TCP buffer overflow Error: TCP buffer overflow Error: TCP buffer overflow Error: TCP buffer overflow Error: Failure to create CGI Process Error: Failure to create CGI Process Error: Failure to create CGI Process Error: Failure to create CGI Process Error: Failure to create CGI Process Error: Failure to create CGI Process Error: Failure to create CGI Process Error: Failure to create CGI Process Error: Failure to create CGI Process Tested: Windows 2000 / Savant 3.0 Vulnerable: Savant 3.0 (And may be other) Disclaimer: http://www.securityoffice.net is not responsible for the misuse or illegal use of any of the information and/or the software listed on this security advisory. Author: Tamer Sahin ts@securityoffice.net http://www.securityoffice.net Tamer Sahin http://www.securityoffice.net PGP Key ID: 0x2B5EDCB0 Fingerprint: B96A 5DFC E0D9 D615 8D28 7A1B BB8B A453 2B5E DCB0 -----BEGIN PGP SIGNATURE----- Version: PGPfreeware 6.5.3 for non-commercial use iQA/AwUBPDcsyLuLpFMrXtywEQILHQCePykGavuFDzyuhv3QEJvJj69IT2gAn0w0 N2KarHO/eJUF9oapdNikgNam =gpy0 -----END PGP SIGNATURE-----