mini_httpd: Arbitrary code execution
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 201206-27 / mini_httpd |
| Release Date |
June 24, 2012 |
| Latest Revision |
June 24, 2012: 1 |
| Impact |
normal |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| www-servers/mini_httpd |
revision <=
1.19 |
|
All supported architectures
|
Related bugreports:
#303755
Synopsis
A vulnerability in mini_httpd could allow remote attackers to
execute arbitrary code.
2.
Impact Information
Background
mini_httpd is a small webserver with optional SSL and IPv6 support.
Description
mini_httpd does not properly check for shell escapes when parsing HTTP
requests.
Impact
A remote attacker could send specially crafted HTTP requests, possibly
resulting in execution of arbitrary code with the privileges of the
process, or allowing for overwriting of files.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
Gentoo discontinued support for mini_httpd. We recommend that users
unmerge mini_httpd:
Code Listing 3.1: Resolution |
# emerge --unmerge "www-servers/mini_httpd"
|
4.
References
|