PT-2009-5935 · Httpdx · Httpdx Web Server
Published
2009-10-11
·
Updated
2017-09-19
·
CVE-2009-3663
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
httpdx Web Server version 1.4
Description
The issue is related to a format string vulnerability in the h readrequest function. This vulnerability can be exploited by remote attackers who send format string specifiers in the Host header, potentially causing a denial of service or allowing the execution of arbitrary code.
Recommendations
For httpdx Web Server version 1.4, consider disabling the h readrequest function until a patch is available to prevent potential exploitation. Restrict access to the httpdx Web Server to minimize the risk of denial of service or arbitrary code execution.
Exploit
Fix
Use of Externally-Controlled Format String
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Httpdx Web Server