vendor:
Yaws
by:
Praveen Dar$hanam
7.8
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Yaws
Affected Version From: 1.79
Affected Version To: 1.79
Patch Exists: YES
Related CWE: CVE-2009-0751
CPE: yaws
Metasploit:
N/A
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=35924, https://www.infosecmatter.com/nessus-plugin-library/?id=93132, https://www.infosecmatter.com/nessus-plugin-library/?id=88499, https://www.infosecmatter.com/nessus-plugin-library/?id=88613, https://www.infosecmatter.com/nessus-plugin-library/?id=88612, https://www.infosecmatter.com/nessus-plugin-library/?id=88532, https://www.infosecmatter.com/nessus-plugin-library/?id=99128, https://www.infosecmatter.com/nessus-plugin-library/?id=11748
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2009
Yaws before 1.80 Denial of Service Vulnerability
Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with a large number of headers.
Mitigation:
Upgrade to Yaws version 1.80 or later.