CVE-2008-5421

Severity CVSS v4.0:
Pending analysis
Type:
CWE-399 Resource Management Errors
Publication date:
11/12/2008
Last modified:
09/04/2025

Description

The SSL web administration service in NetWin SmsGate 1.1n and earlier allows remote attackers to cause a denial of service (hang) via (1) a large integer in the Content-Length HTTP header; (2) an invalid value in the Content-Length HTTP header, as demonstrated by a negative integer; or (3) a missing Content-Length HTTP header.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:netwin:smsgate:*:*:*:*:*:*:*:* 1.1n (including)
cpe:2.3:a:netwin:smsgate:1.0a:*:*:*:*:*:*:*
cpe:2.3:a:netwin:smsgate:1.0c:*:*:*:*:*:*:*
cpe:2.3:a:netwin:smsgate:1.0h:*:*:*:*:*:*:*
cpe:2.3:a:netwin:smsgate:1.0r:*:*:*:*:*:*:*
cpe:2.3:a:netwin:smsgate:1.0w:*:*:*:*:*:*:*
cpe:2.3:a:netwin:smsgate:1.1m:*:*:*:*:*:*:*