Nessus Plugin #15233

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

[DSA396] DSA-396-1 thttpd

Family:
Debian Local Security Checks
Category:
infos
Copyright:
This script is (C) 2004 Michel Arboi
Summary:
DSA-396-1 thttpd
Version:
$Revision: 1.4 $
Cve_id:
CAN-2002-1562, CAN-2003-0899
Bugtraq_id:
8906, 8924
Xrefs:
DSA:396
Description:

Several vulnerabilities have been discovered in thttpd, a tiny HTTP
server.
The Common Vulnerabilities and Exposures project identifies the
following vulnerabilities:
Marcus Breiing discovered that if thttpd it is used for virtual
hosting, and an attacker supplies a specially crafted &ldquo
Host:&rdquo

header with a pathname instead of a hostname, thttpd will reveal
information about the host system. Hence, an attacker can browse
the entire disk.
Joel S÷derberg and Christer ╓berg discovered a remote overflow which
allows an attacker to partially overwrite the EBP register and
hence execute arbitrary code.
For the stable distribution (woody) these problems have been fixed in
version 2.21b-11.2.
For the unstable distribution (sid) these problems have been fixed in
version 2.23beta1-2.3.
We recommend that you upgrade your thttpd package immediately.


Solution : http://www.debian.org/security/2003/dsa-396
Risk factor : High
Generiert am 27.04.2005 um 18:49:54 Uhr.