Multiple buffer overflows in Tomahawk SteelArrow before 4.5 allow remote attackers to execute arbitrary code via (1) the Steelarrow Service (Steelarrow.exe) using a long UserIdent Cookie header, (2) DLLHOST.EXE (Steelarrow.dll) via a request for a long .aro file, or (3) DLLHOST.EXE via a Chunked Transfer-Encoding request.
References
Configurations
Information
Published : 2003-04-10 21:00
Updated : 2008-09-05 13:30
NVD link : CVE-2002-1441
Mitre link : CVE-2002-1441
JSON object : View
CWE
Products Affected
tomahawk_technologies
- steelarrow