thttpd v2.26 Stack-Based Buffe... Note

thttpd v2.26 Stack-Based Buffer Overflow in thttpd redirect CGI Program

Posted by Ron E on Sep 03Description: A stack-based buffer overflow vulnerability exists in the redirect CGI program distributed with thttpd. The vulnerability is caused by unsafe string concatenation when constructing redirect URLs using attacker-controlled CGI environment variables. A remote, unauthenticated attacker can trigger the vulnerability via a crafted HTTP request, resulting in a crash of the CGI process and denial of service. In environments lacking modern...