LWN.net Logo

mini-httpd: code execution

Package(s):mini-httpd CVE #(s):CVE-2009-4490
Created:June 25, 2012 Updated:June 27, 2012
Description: From the Gentoo advisory:

mini_httpd does not properly check for shell escapes when parsing HTTP requests.

A remote attacker could send specially crafted HTTP requests, possibly resulting in execution of arbitrary code with the privileges of the process, or allowing for overwriting of files.

Alerts:
Gentoo 201206-27 2012-06-24

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds