PT-2007-4442 · Miniweb · Miniweb Http Server

Gbr

·

Published

2007-06-11

·

Updated

2017-10-11

·

CVE-2007-3159

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: MiniWeb Http Server versions 0.8.x
Description: The issue allows remote attackers to cause a denial of service, resulting in an application crash. This is achieved by sending a negative value in the Content-Length HTTP header.
Recommendations: For MiniWeb Http Server versions 0.8.x, consider validating the Content-Length header to prevent negative values until a patch is available. As a temporary workaround, restrict access to the HTTP server to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3159

Affected Products

Miniweb Http Server