thttpd tdate_parse()堆溢出漏洞

漏洞信息详情

thttpd tdate_parse()堆溢出漏洞

漏洞简介

Trivial HTTP (THTTPd)存在缓冲区溢出漏洞。远程攻击者借助超长If-Modified-Since头导致服务拒绝或者执行任意命令。

漏洞公告

Upgrade to version 2.0.5 or later.
S.u.S.E. has released upgrade RPMs for thttpd, which shipped as an optional package with S.u.S.E. Linux 6.2/6.3.
Acme thttpd 2.0.4

参考网址

来源: BID
名称: 1248
链接:http://www.securityfocus.com/bid/1248

来源: SUSE
名称: 19991116 Security hole in thttpd 1.90a – 2.04
链接:http://www.novell.com/linux/security/advisories/suse_security_announce_30.html

来源: BUGTRAQ
名称: 19991113 thttpd 2.04 stack overflow (VD#6)
链接:http://archives.neohapsis.com/archives/bugtraq/1626.html

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享