Junglewise Threat Intelligence

CVE-1999-1207: NetXRay web-admin tool buffer overflow

CVE-1999-1207 · Severity: high · CVSS 7.5 · Published 1998-02-18

Executive brief

A vulnerability in the web-based administration tool of NetXRay, a network analysis and monitoring suite, could allow an attacker to crash the service or take control of the system. By sending a specially crafted, overly long web request, a remote attacker can disrupt network monitoring operations or potentially execute unauthorized commands on the host machine.

Technical details

A classic buffer overflow exists within the web-administration component of NetXRay version 2.6. The vulnerability is triggered when the application fails to properly validate the length of incoming HTTP requests before copying them into a fixed-size memory buffer. A remote, unauthenticated attacker can exploit this by sending a maliciously crafted, oversized HTTP request to the web-admin service. Successful exploitation can lead to a crash of the administration service (Denial of Service) or the execution of arbitrary code with the privileges of the application.

Affected products

  • Cinco Networks NetXRay 2.6

Timeline

  • 1998-02-18: disclosed: Initial public disclosure date

References