Buffer overflows in forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 allows remote attackers to execute arbitrary code via long arguments to the parameters (1) Mode, (2) Certificate_File, (3) useExpiredCRLs, (4) listenLength, (5) maxThread, (6) maxConnPerSite, (7) maxMsgLen, (8) exitTime, (9) blockTime, (10) nextUpdatePeriod, (11) buildLocal, (12) maxOCSPValidityPeriod, (13) extension, and (14) a particular combination of parameters associated with private key generation that form a string of a certain length.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2002-02-02T05:00:00
Updated: 2024-08-08T04:37:06.826Z
Reserved: 2002-01-31T00:00:00
Link: CVE-2001-0949
Vulnrichment
No data.
NVD
Status : Modified
Published: 2001-12-04T05:00:00.000
Modified: 2024-11-20T23:36:30.727
Link: CVE-2001-0949
Redhat
No data.