A remote overflow exists in ADA Image Server 0.4. With a specially crafted request, an attacker can cause an overflow that could allow arbitrary code execution resulting in a loss of integrity and availability.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity,
Loss of Availability
Exploit:
Exploit Public
Disclosure:
OSVDB Verified
Technical
By sending a GET request followed by 2,112 characters, an attacker can cause the web server to crash. By further modifying the request, it may be possible to execute arbitrary code with the same privileges as the web server.
Solution
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.