Nessus Plugin #15233
Plugin Index
Note: This file has been created from a
downloaded version of the Nessus Plugins
from
http://www.nessus.org/.
Therefore, the information here can be outdated.
[DSA396] DSA-396-1 thttpd
- Family:
- Debian Local Security Checks
- Category:
- infos
- Copyright:
- This script is (C) 2004 Michel Arboi
- Summary:
- DSA-396-1 thttpd
- Version:
- $Revision: 1.4 $
- Cve_id:
- CAN-2002-1562, CAN-2003-0899
- Bugtraq_id:
- 8906, 8924
- Xrefs:
- DSA:396
- Description:
Several vulnerabilities have been discovered in thttpd, a tiny HTTP
server.
The Common Vulnerabilities and Exposures project identifies the
following vulnerabilities:
Marcus Breiing discovered that if thttpd it is used for virtual
hosting, and an attacker supplies a specially crafted &ldquo
Host:&rdquo
header with a pathname instead of a hostname, thttpd will reveal
information about the host system. Hence, an attacker can browse
the entire disk.
Joel S÷derberg and Christer ╓berg discovered a remote overflow which
allows an attacker to partially overwrite the EBP register and
hence execute arbitrary code.
For the stable distribution (woody) these problems have been fixed in
version 2.21b-11.2.
For the unstable distribution (sid) these problems have been fixed in
version 2.23beta1-2.3.
We recommend that you upgrade your thttpd package immediately.
Solution : http://www.debian.org/security/2003/dsa-396
Risk factor : High
Generiert am 27.04.2005 um 18:49:54 Uhr.