|
Internet Security Systems' Internet Security Scanner contains a buffer overflow that allows a remote attacker to cause a denial of service and potentially execute arbitrary code. The ISS web scanning module fails to sanitize input during the license banner HTTP check as it scans a remote host.If an attacker created a custom web server, they could send data that would overflow the buffer causing a denial of service by crashing the scanning application. It may be possible to use this flaw to execute arbitrary code, but it has not been confirmed.
|