ZeroHour
Full Disclosurepublished ()ingested

thttpd v2.26 Stack-Based Buffer Overflow in thttpd redirect CGI Program

mediumVulnerabilityimportance 25
AI summary · glm-5.3-flash

The redirect CGI program shipped with thttpd v2.26 has a stack buffer overflow that unauthenticated attackers can trigger for crashes or possible code execution.

A stack-based buffer overflow exists in the redirect CGI program distributed with thttpd v2.26. Unsafe string concatenation when constructing redirect URLs from attacker-controlled CGI environment variables causes the overflow. A remote, unauthenticated attacker can trigger it via a crafted HTTP request, crashing the CGI process and causing denial of service. In environments lacking modern exploit mitigations, code execution may also be possible.

  • Unsafe string concatenation of CGI environment variables builds redirect URLs
  • Remote unauthenticated attackers can crash the CGI process, causing denial of service
  • Code execution is possible in environments lacking modern exploit mitigations
Vendorsthttpd
Productsthttpd
Full article

Posted by Ron E on Sep 03 *Description:* A stack-based buffer overflow vulnerability exists in the redirect CGI program distributed with thttpd. The vulnerability is caused by unsafe string concatenation when constructing redirect URLs using attacker-controlled CGI environment variables. A remote, unauthenticated attacker can trigger the vulnerability via a crafted HTTP request, resulting in a crash of the CGI process and denial of service. In environments lacking modern...

This source does not provide full text. Read it at seclists.org.