Junglewise Threat Intelligence

CVE-1999-0235: NCSA WebServer buffer overflow leading to remote access

CVE-1999-0235 · Severity: critical · CVSS 10 · Published 1995-02-17

Technologies: Ncsa WebServer. Vendors: Ncsa.

Executive brief

A critical vulnerability exists in the NCSA WebServer, an early web server software. An attacker can exploit this flaw to gain full remote access to the server over the internet. This could lead to a complete compromise of the system, including the theft of data or the disruption of hosted services.

Technical details

A buffer overflow vulnerability exists in NCSA WebServer versions 1.4.1 and prior. The flaw is reachable over the network without authentication, allowing a remote attacker to execute arbitrary code or gain a shell on the affected host. This is a classic stack-based or heap-based overflow resulting from improper bounds checking on input. Successful exploitation grants the attacker full control over the server process, typically with the privileges of the user running the web server daemon.

Affected products

  • NCSA WebServer 1.4.1 and below

Timeline

  • 1995-02-17: disclosed

References

Related threats