Release date: 2011-10-14
Updated on: 2011-10-14
Affected Systems:
G-WAN 2.10.6
Description:
--------------------------------------------------------------------------------
G-WAN is a small, fast and secure Web server, Web application server, Web Acceleration Server, KV store and noSQL database.
G-WAN has multiple vulnerabilities in design, resolution, signal processing and buffer management. Remote attackers can exploit these vulnerabilities to execute shellcode, resulting in DOS.
1) The buffer overflow vulnerability exists when processing the URL encoding of the csp subdirectory.
2) The SIGPIPE signal is incorrectly processed.
<* Source: Fredrik Widlund
Link: http://seclists.org/bugtraq/2011/Oct/83
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
G-WAN
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://gwan.com