Логотип exploitDog
bind:CVE-2021-26843
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-26843

Количество 3

Количество 3

nvd логотип

CVE-2021-26843

около 5 лет назад

An issue was discovered in sthttpd through 2.27.1. On systems where the strcpy function is implemented with memcpy, the de_dotdot function may cause a Denial-of-Service (daemon crash) due to overlapping memory ranges being passed to memcpy. This can triggered with an HTTP GET request for a crafted filename. NOTE: this is similar to CVE-2017-10671, but occurs in a different part of the de_dotdot function.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2021-26843

около 5 лет назад

An issue was discovered in sthttpd through 2.27.1. On systems where th ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-67j3-q5rv-5gjr

больше 3 лет назад

An issue was discovered in sthttpd through 2.27.1. On systems where the strcpy function is implemented with memcpy, the de_dotdot function may cause a Denial-of-Service (daemon crash) due to overlapping memory ranges being passed to memcpy. This can triggered with an HTTP GET request for a crafted filename. NOTE: this is similar to CVE-2017-10671, but occurs in a different part of the de_dotdot function.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-26843

An issue was discovered in sthttpd through 2.27.1. On systems where the strcpy function is implemented with memcpy, the de_dotdot function may cause a Denial-of-Service (daemon crash) due to overlapping memory ranges being passed to memcpy. This can triggered with an HTTP GET request for a crafted filename. NOTE: this is similar to CVE-2017-10671, but occurs in a different part of the de_dotdot function.

CVSS3: 7.5
0%
Низкий
около 5 лет назад
debian логотип
CVE-2021-26843

An issue was discovered in sthttpd through 2.27.1. On systems where th ...

CVSS3: 7.5
0%
Низкий
около 5 лет назад
github логотип
GHSA-67j3-q5rv-5gjr

An issue was discovered in sthttpd through 2.27.1. On systems where the strcpy function is implemented with memcpy, the de_dotdot function may cause a Denial-of-Service (daemon crash) due to overlapping memory ranges being passed to memcpy. This can triggered with an HTTP GET request for a crafted filename. NOTE: this is similar to CVE-2017-10671, but occurs in a different part of the de_dotdot function.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу