1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




NaviCOPA Script Source Disclosure and Buffer Overflow Vulnerabilities

Report ID: SA200900669
Source: Secunia
Date of Discovery: 05.02.2009
Criticality: Urgent
Affects:
NaviCOPA 3.x

Compromise From: From remote
Compromise Type: Exposure of sensitive information
System access
DoS

Summary

Two vulnerabilities has been discovered in NaviCOPA, which can be exploited by malicious people to disclose potentially sensitive information, cause a DoS (Denial of Service), or potentially compromise a vulnerable system.

Detailed Description

1) A boundary error in the processing of HTTP requests can be exploited to cause a heap-based buffer overflow via an overly long HTTP GET request.

Successful exploitation may allow execution of arbitrary code.

2) An error when processing HTTP requests can be exploited to retrieve the source code of e.g. PHP scripts via specially crafted requests containing e.g. dot characters.

The vulnerabilities are confirmed in version 3.01. Other versions may also be affected.

Solution

Restrict access to trusted users only.