Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:OVERFLOW:AUTH-OVERFLOW

Severity

High

Recommended

Yes

Recommended Action

Drop

Category

HTTP

Keywords

Authorization Header Overflow

Release Date

2010/04/27

Update Number

1668

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Authorization Header Overflow


This signature detects an overly long HTTP "Authorization" header field value. This type of attack is most likely an attempt to exploit a buffer overflow condition in a Web server.

Extended Description

In a paper titled "Variations in exploit methods between Linux and Windows" presented at Blackhat 2003, David Litchfield has illustrated multiple vulnerabilities in the Oracle 9i XML Database (XDB). Successful exploits may allow remote attackers to run arbitrary code in the security context of the vulnerable service.

Affected Products

  • Oracle Oracle9i Enterprise Edition 9.2.0 .0.1
  • Oracle Oracle9i Personal Edition 9.2.0 .0.1
  • Oracle Oracle9i Standard Edition 9.2.0 .0.1

References

  • BugTraq: 8375
  • CVE: CVE-2009-0183
  • CVE: CVE-2003-0727

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out