vendor:
LibHTTPD
by:
Xpl017Elz
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: LibHTTPD
Affected Version From: 1.2
Affected Version To: 1.2
Patch Exists: YES
Related CWE: N/A
CPE: a:libhttpd:libhttpd:1.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2002
LibHTTPD Remote Buffer Overflow
LibHTTPD is vulnerable to a buffer overflow condition. By passing a POST request of excessive length, it is possible to overrun a static buffer. This may result in sensitive locations in memory being overwritten by attacker-supplied values. Successful exploitation of this vulnerability may allow an attacker to execute arbitrary code with super user privileges.
Mitigation:
Upgrade to the latest version of LibHTTPD.