vendor:
thttpd
by:
SecurityFocus
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: thttpd
Affected Version From: 2.21
Affected Version To: 2.23b1
Patch Exists: YES
Related CWE: N/A
CPE: thttpd
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
thttpd Remote Code Execution Vulnerability
A vulnerability has been reported in thttpd that may allow a remote attacker to execute arbitrary code on vulnerable host. The issue is reported to exist due to a lack of bounds checking by software, leading to a buffer overflow condition. The problem is reported to exist in the defang() function in libhttpd.c.
Mitigation:
Upgrade to the latest version of thttpd.