vendor:
thttpd
by:
d3ck4
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: thttpd
Affected Version From: 2.21
Affected Version To: 2.23b1
Patch Exists: YES
Related CWE: N/A
CPE: thttpd
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: FreeBSD, SunOS 4, Solaris 2, BSD/OS, Linux, OSF
2003
thttpd Remote Denial of Service Vulnerability
A vulnerability has been reported in thttpd that may allow a remote attacker to execute arbitrary code on vulnerable host. The issue is reported to exist due to a lack of bounds checking by software, leading to a buffer overflow condition. The problem is reported to exist in the defang() function in libhttpd.c. This issue may allow an attacker to gain unauthorized access to a vulnerable host. Successful exploitation of this issue may allow an attacker to execute arbitrary code in the context of the web server in order to gain unauthorized access to a vulnerable system.
Mitigation:
Upgrade to version 2.24