ignore security and it'll go away

activeperl.516.dos.txt

activeperl.516.dos.txt
Posted Aug 17, 1999

ActivePerl v516 and earlier for Windows IIS leave the server vulnerable to denial of service attacks. Exploit description included.

tags | exploit, denial of service
systems | windows
MD5 | 57ee4e95363a4c81d5194c6b2ae7d2a9

activeperl.516.dos.txt

Change Mirror Download
Date: Mon, 31 May 1999 07:16:53 -0700
From: Michael Smith <support@ACTIVESTATE.COM>
To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
Subject: ActiveState Security Advisory

Problem
--------

PerlScript and Perl-ISAPI that come with ActivePerl 516 and earlier
versions, inadequately check the length of path information sent to open().
Due to limits on path and filename length in Windows, this can crash IIS
if sufficiently large strings are provided as paths or filenames.



Solution
---------

This is fixed in ActivePerl 517



Work Around
------------

If you are unable to upgrade to ActivePerl 517 then all path information
should be checked for sane lengths before being passed to open(). The
maximum length of a path, including drive, directory and filename is 259
characters. The maximum length of the filename portion of a path is 255
characters. The maximum length of the directory portion of a path is 255
characters.

example:

$filename = substr $filename, 0, 255;
open FOO, ">$filename";



General Comments
-----------------

Care should be taken when accepting input from users, especially in a web
context where users are untrusted and relatively anonymous. When designing
CGI scripts some thought should be given to checking user input for sane
values. Use of taint mode and warnings (-t and -w) are also highly
recommended.

The Activators.

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close