CVE-2001-0949
Last modified
CVE-2001-0949 is a vulnerability of currently unknown severity. Buffer overflows in forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 allows remote attackers to execute arbitrary code via long arguments to the parameters (1) Mode, (2) Certificate_File, (3) useExpiredCRLs, (4) listenLength, (5) maxThread, (6) maxConnPerSite, (7) maxMsgLen, (8) exitTime, (9) blockTime, (10) nextUpdatePeriod, (11) buildLocal, (12) maxOCSPValidityPeriod, (13) extension, and (14) a particular combination of parameters associated with private key generation that form a string of a certain length.. EPSS estimates a 4.06% chance of exploitation in the next 30 days.
Description
Buffer overflows in forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 allows remote attackers to execute arbitrary code via long arguments to the parameters (1) Mode, (2) Certificate_File, (3) useExpiredCRLs, (4) listenLength, (5) maxThread, (6) maxConnPerSite, (7) maxMsgLen, (8) exitTime, (9) blockTime, (10) nextUpdatePeriod, (11) buildLocal, (12) maxOCSPValidityPeriod, (13) extension, and (14) a particular combination of parameters associated with private key generation that form a string of a certain length.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Valicert | Enterprise Validation Authority | 3.3 |
| Valicert | Enterprise Validation Authority | 3.4 |
| Valicert | Enterprise Validation Authority | 3.5 |
| Valicert | Enterprise Validation Authority | 3.6 |
| Valicert | Enterprise Validation Authority | 3.7 |
| Valicert | Enterprise Validation Authority | 3.8 |
| Valicert | Enterprise Validation Authority | 3.9 |
| Valicert | Enterprise Validation Authority | 4.0 |
| Valicert | Enterprise Validation Authority | 4.1 |
| Valicert | Enterprise Validation Authority | 4.2 |
| Valicert | Enterprise Validation Authority | 4.2.1 |
References
- http://www.securityfocus.com/bid/3621Patch, Vendor Advisory
- http://www.valicert.com/support/security_advisory_eva.htmlVendor Advisory, URL Repurposed
- http://www.securityfocus.com/bid/3621Patch, Vendor Advisory
- http://www.valicert.com/support/security_advisory_eva.htmlVendor Advisory, URL Repurposed
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2001-0949?
How severe is CVE-2001-0949?
How do I fix CVE-2001-0949?
Are you affected by CVE-2001-0949?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
