Acme thttpd/mini_httpd虚拟主机文件泄漏漏洞

漏洞信息详情

Acme thttpd/mini_httpd虚拟主机文件泄漏漏洞

漏洞简介

thttpd存在目录遍历漏洞。当使用虚拟主机时远程攻击者可以借助Host: header的..(点 点)读取任意文件。

漏洞公告

SuSE has released an advisory (SuSE-SA:2003:044) to address this issue in SuSE Linux platforms. Affected users are advised to apply fixes as soon as possible. Further information regarding obtaining and applying these fixes can be found in the referenced advisory.
Debian has released an advisory (DSA 396-1) and fixes to address this issue in thttpd.
Conectiva has released a security advisory (CLA-2003:777) which contains fixes to address this issue. Users are advised to upgrade as soon as possible.
This issue has been addressed in thttpd 2.24 and mini_httpd 1.18.
Acme mini_httpd 1.0 0

Acme mini_httpd 1.0 1

Acme thttpd 1.0

Acme mini_httpd 1.10 0

Acme mini_httpd 1.11

Acme mini_httpd 1.12

Acme mini_httpd 1.13

Acme mini_httpd 1.14

Acme mini_httpd 1.15 b

Acme mini_httpd 1.15 c

Acme mini_httpd 1.15

Acme mini_httpd 1.16

Acme thttpd 1.90 a

Acme thttpd 1.95

Acme thttpd 2.0

Acme thttpd 2.0.1

Acme thttpd 2.0.2

Acme thttpd 2.0.3

Acme thttpd 2.0.4

Acme thttpd 2.0.5

Acme thttpd 2.0.6

Acme thttpd 2.0.7

Acme thttpd 2.0.8

Acme thttpd 2.0.9

Acme thttpd 2.10

Acme thttpd 2.11

Acme thttpd 2.12

Acme thttpd 2.13

Acme thttpd 2.14

Acme thttpd 2.15

Acme thttpd 2.16

Acme thttpd 2.17

Acme thttpd 2.18

  • Acme thttpd-2.24.tar.gz

参考网址

来源: news.php.net
链接:http://news.php.net/article.php?group=php.cvs&article=15698

来源: marc.theaimsgroup.com
链接:http://marc.theaimsgroup.com/?l=thttpd&m=103609565110472&w=2

来源: DEBIAN
名称: DSA-396
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=106744982732304&w=2

来源: CONECTIVA
名称: CLA-2003:777
链接:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000777

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享