vendor:
CoreHTTP Web Server
by:
Patroklos Argyroudis
7.5
CVSS
HIGH
Denial of Service
20
CWE
Product Name: CoreHTTP Web Server
Affected Version From: 0.5.3.1
Affected Version To: 0.5.3.1
Patch Exists: YES
Related CWE: CVE-2009-3586
CPE: a:corehttp:corehttp_web_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2009
CoreHTTP Web Server Denial of Service Vulnerability
The CoreHTTP web server versions buffer, 46: "%" PATHSIZE_S "[A-Za-z] %" PATHSIZE_S "s%*[ ]", req, url); contains a vulnerability that can lead to denial of service attacks against the CoreHTTP web server and potentially to the remote execution of arbitrary code with the privileges of the user running the server. A proof-of-concept exploit has been developed to demonstrate the vulnerability.
Mitigation:
A workaround can be used until an official fix is released by the author.