Junglewise Threat Intelligence

CVE-1999-0232: NCSA WebServer buffer overflow allows remote access

CVE-1999-0232 · Severity: critical · CVSS 10 · Published 1995-02-01

Technologies: Ncsa WebServer. Vendors: Ncsa.

Executive brief

A critical security flaw exists in the NCSA WebServer, an early software used to host websites. This vulnerability allows a remote attacker to gain full control over the server without needing a password. An exploit could lead to the complete theft of data, website defacement, or the use of the server to launch further attacks.

Technical details

A buffer overflow vulnerability exists in NCSA WebServer (NCSA httpd) version 1.5c. The flaw is located in the handling of incoming network requests, where insufficient bounds checking allows an attacker to overwrite memory. A remote, unauthenticated attacker can exploit this by sending a specially crafted request to the server. Successful exploitation results in arbitrary code execution with the privileges of the web server process, leading to full system compromise.

Affected products

  • NCSA WebServer 1.5c

Timeline

  • 1995-02-01: disclosed: Initial publication date in NVD.

References

Related threats