ABB IDAL HTTP Server Stack-Based Buffer Overflow
Posted by deepcore on June 25, 2019 – 1:59 pm
The IDAL HTTP server is vulnerable to a stack-based buffer overflow when receiving a large host header in a HTTP request. The host header value overflows a buffer and overwrites the Structured Exception Handler (SEH) address with a larger buffer. An unauthenticated attacker can send a Host header value of 2047 bytes or more to overflow the host headers and overwrite the SEH address which can then be leveraged to execute attacker controlled code on the server.
Post a reply
You must be logged in to post a comment.