Description
The webserver is vulnerable to a denial of service condition. An unauthenticated remote attacker can craft a special GET request with an over-long content-length to trigger the issue without affecting the core functionality.
Problem types
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
VC:00 before VC:07
VC:00 before VC:07
VC:00 before VC:07
VC:00 before VC:07
Credits
D. Blagojevic, S. Dietz, F. Koroknai, T. Weber from CyberDanube Security Research
References
certvde.com/de/advisories/VDE-2025-072