Acme · Mini Httpd · CVE-2015-1548
**Name of the Vulnerable Software and Affected Versions**
mini httpd versions 1.21 and earlier
**Description**
The issue allows remote attackers to obtain sensitive information from process memory via an HTTP request with a long protocol string. This occurs because the long protocol string triggers an incorrect response size calculation and an out-of-bounds read.
**Recommendations**
For mini httpd versions 1.21 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.