Buffer overflow in BRS WebWeaver 1.06 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP request with a long User-Agent header.
| Software | From | Fixed in |
|---|---|---|
| brs / webweaver | 1.0.4 | 1.0.4.x |
| brs / webweaver | 1.0.6 | 1.0.6.x |
| brs / webweaver | 1.0.3 | 1.0.3.x |
| brs / webweaver | 0.50_beta | 0.50_beta.x |
| brs / webweaver | 0.60_beta | 0.60_beta.x |
| brs / webweaver | 0.52_beta | 0.52_beta.x |
| brs / webweaver | 0.63_beta | 0.63_beta.x |
| brs / webweaver | 0.51_beta | 0.51_beta.x |
| brs / webweaver | 0.62_beta | 0.62_beta.x |
| brs / webweaver | 0.61_beta | 0.61_beta.x |
| brs / webweaver | 1.0.5 | 1.0.5.x |
| brs / webweaver | 0.49_beta | 0.49_beta.x |
| brs / webweaver | 1.0.2 | 1.0.2.x |
| brs / webweaver | 1.0.1 | 1.0.1.x |