Vulnerability Description
The webmail service in 602 Lan Suite 2004.0.04.0909 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) by sending a POST request with a large Content-Length value, then disconnecting without sending that amount of data.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Software602 | 602Lan Suite | <= 2004.0.04.0909 |
References
- http://marc.info/?l=bugtraq&m=109976745017459&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17977
- http://marc.info/?l=bugtraq&m=109976745017459&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17977
FAQ
What is CVE-2004-1501?
CVE-2004-1501 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The webmail service in 602 Lan Suite 2004.0.04.0909 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) by sending a POST request with a large Content-Length ...
How severe is CVE-2004-1501?
CVE-2004-1501 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-1501?
Check the references section above for vendor advisories and patch information. Affected products include: Software602 602Lan Suite.