J-Security Center

Title: MyWebServer Search Request Remote Buffer Overflow Vulnerability

Severity: CRITICAL

Description:

MyWebServer is an application and web server for Microsoft Windows operating systems. MyWebServer includes a number of web based functions, including a search engine.

MyWebServer suffers from a remote buffer overflow vulnerability. If a parameter longer than 990 characters is submitted to the included search engine, this condition will be exploited.

It has been reported possible to corrupt process memory such that arbitrary, attacker supplied code is executed as the server process. Exploitation may result in the attacker gaining local access to the vulnerable system as the MyWebServer process. Sending arbitrary data may cause the server process to crash, creating a denial of service condition.

This vulnerability has been reported in MyWebServer version 1.0.2. Earlier versions may share this vulnerability, this has not however been confirmed.

Affected Products:

  • MyWebServer MyWebServer 1.0.2

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.