cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
314
Views
0
Helpful
1
Replies

Signature 5245 "HTTP 1.1 Chunked Encoding Transfer"

astuckey
Level 1
Level 1

Does this signature provide coverage for CVE list candidate CAN-2002-0845?

This CVE number is not referenced in the NSDB description.

1 Accepted Solution

Accepted Solutions

mcerha
Level 3
Level 3

Yes, 5245 should provide coverage for this vulnerability. HTTP chunked encoding is a rarely used feature of the HTTP protocol, so we felt it better to write a generic signature to cover a range of similar buffer overflow problems than to author specific narrow signatures.

View solution in original post

1 Reply 1

mcerha
Level 3
Level 3

Yes, 5245 should provide coverage for this vulnerability. HTTP chunked encoding is a rarely used feature of the HTTP protocol, so we felt it better to write a generic signature to cover a range of similar buffer overflow problems than to author specific narrow signatures.