CVE-2010-0359 Information

Description

Buffer overflow in the SSLv2 support in Zeus Web Server before 4.3r5 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long string in an invalid Client Hello message.

Reference

http://intevydis.blogspot.com/2010/01/zeus-web-server-ssl2clienthello.html http://intevydis.com/vd-list.shtml http://secunia.com/advisories/38056 http://securitytracker.com/id?1023465 http://support.zeus.com/zws/media/docs/4.3/RELEASE_NOTES http://support.zeus.com/zws/news/2010/01/13/zws_4_3r5_released http://www.osvdb.org/61699 http://www.securityfocus.com/bid/37829 http://www.vupen.com/english/advisories/2010/0147

Share on: