Описание
mini_httpd 1.21 and earlier allows remote attackers to obtain sensitive information from process memory via an HTTP request with a long protocol string, which triggers an incorrect response size calculation and an out-of-bounds read.
Уязвимые конфигурации
Конфигурация 1Версия до 1.21 (включая)
cpe:2.3:a:acme:mini_httpd:*:*:*:*:*:*:*:*
EPSS
Процентиль: 74%
0.016
Низкий
5 Medium
CVSS2
Дефекты
CWE-119
Связанные уязвимости
debian
больше 11 лет назад
mini_httpd 1.21 and earlier allows remote attackers to obtain sensitiv ...
github
больше 4 лет назад
mini_httpd 1.21 and earlier allows remote attackers to obtain sensitive information from process memory via an HTTP request with a long protocol string, which triggers an incorrect response size calculation and an out-of-bounds read.
EPSS
Процентиль: 74%
0.016
Низкий
5 Medium
CVSS2
Дефекты
CWE-119