CVE-2001-0949

Buffer overflows in forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 allows remote attackers to execute arbitrary code via long arguments to the parameters (1) Mode, (2) Certificate_File, (3) useExpiredCRLs, (4) listenLength, (5) maxThread, (6) maxConnPerSite, (7) maxMsgLen, (8) exitTime, (9) blockTime, (10) nextUpdatePeriod, (11) buildLocal, (12) maxOCSPValidityPeriod, (13) extension, and (14) a particular combination of parameters associated with private key generation that form a string of a certain length.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:valicert:enterprise_validation_authority:3.3:*:*:*:*:*:*:*
cpe:2.3:a:valicert:enterprise_validation_authority:3.4:*:*:*:*:*:*:*
cpe:2.3:a:valicert:enterprise_validation_authority:3.5:*:*:*:*:*:*:*
cpe:2.3:a:valicert:enterprise_validation_authority:3.6:*:*:*:*:*:*:*
cpe:2.3:a:valicert:enterprise_validation_authority:3.7:*:*:*:*:*:*:*
cpe:2.3:a:valicert:enterprise_validation_authority:3.8:*:*:*:*:*:*:*
cpe:2.3:a:valicert:enterprise_validation_authority:3.9:*:*:*:*:*:*:*
cpe:2.3:a:valicert:enterprise_validation_authority:4.0:*:*:*:*:*:*:*
cpe:2.3:a:valicert:enterprise_validation_authority:4.1:*:*:*:*:*:*:*
cpe:2.3:a:valicert:enterprise_validation_authority:4.2:*:*:*:*:*:*:*
cpe:2.3:a:valicert:enterprise_validation_authority:4.2.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2001-12-04 05:00

Updated : 2024-02-14 01:17


NVD link : CVE-2001-0949

Mitre link : CVE-2001-0949

CVE.ORG link : CVE-2001-0949


JSON object : View

Products Affected

valicert

  • enterprise_validation_authority