PT-2009-5935 · Httpdx · Httpdx Web Server

Published

2009-10-11

·

Updated

2017-09-19

·

CVE-2009-3663

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions httpdx Web Server version 1.4
Description The issue is related to a format string vulnerability in the h readrequest function. This vulnerability can be exploited by remote attackers who send format string specifiers in the Host header, potentially causing a denial of service or allowing the execution of arbitrary code.
Recommendations For httpdx Web Server version 1.4, consider disabling the h readrequest function until a patch is available to prevent potential exploitation. Restrict access to the httpdx Web Server to minimize the risk of denial of service or arbitrary code execution.

Exploit

Fix

Use of Externally-Controlled Format String

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-3663

Affected Products

Httpdx Web Server