|
|
| |
|
| |
mini-httpd: code execution
| Package(s): | mini-httpd |
CVE #(s): | CVE-2009-4490
|
| Created: | June 25, 2012 |
Updated: | June 27, 2012 |
| Description: |
From the Gentoo advisory:
mini_httpd does not properly check for shell escapes when parsing HTTP
requests.
A remote attacker could send specially crafted HTTP requests, possibly
resulting in execution of arbitrary code with the privileges of the
process, or allowing for overwriting of files. |
| Alerts: |
|
( Log in to post comments)
|
|
|