ghttpd Daemon Buffer Overflow Vulnerability
BID:2879
Info
ghttpd Daemon Buffer Overflow Vulnerability
| Bugtraq ID: | 2879 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2001-0820 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 17 2001 12:00AM |
| Updated: | Jul 11 2009 06:56AM |
| Credit: | This vulnerability was discovered by qitest1 <[email protected]> and submitted to BugTraq on June 17th, 2001. |
| Vulnerable: |
ghttpd ghttpd 1.4.3 ghttpd ghttpd 1.4.2 ghttpd ghttpd 1.4.1 ghttpd ghttpd 1.4 |
| Not Vulnerable: | |
Discussion
ghttpd Daemon Buffer Overflow Vulnerability
ghttpd is a freely available, open source web server for Unix systems. ghttpd supports CGI and is easy to configure and use.
A buffer overflow is known to exist in ghttp which will allow arbitrary code to be executed with the privileges of the webserver.
Proof-of-concept code has demonstrated that this vulnerability can be exploited by remote attackers.
ghttpd is a freely available, open source web server for Unix systems. ghttpd supports CGI and is easy to configure and use.
A buffer overflow is known to exist in ghttp which will allow arbitrary code to be executed with the privileges of the webserver.
Proof-of-concept code has demonstrated that this vulnerability can be exploited by remote attackers.
Exploit / POC
ghttpd Daemon Buffer Overflow Vulnerability
qitest1 <[email protected]> wrote and submitted this proof-of-concept exploit:
qitest1 <[email protected]> wrote and submitted this proof-of-concept exploit:
Solution / Fix
ghttpd Daemon Buffer Overflow Vulnerability
Solution:
The following is an unofficial patch for ghttpd 1.4.2 provided by Marc Pompl:
ghttpd ghttpd 1.4.2
Solution:
The following is an unofficial patch for ghttpd 1.4.2 provided by Marc Pompl:
ghttpd ghttpd 1.4.2
-
Marc Pompl ghttpd-1.4.diff
http://lynorics.sundawn.net/prog/ghttpd-1.4.diff