PT-2010-1406 · Alonso Fernández · Cherokee Web Server

0X90

+1

·

Published

2010-01-07

·

Updated

2018-10-10

·

CVE-2009-4587

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Cherokee Web Server version 0.5.4
Description The issue allows remote attackers to cause a denial of service, resulting in the daemon crashing. This can be achieved by including an MS-DOS reserved word in a URI. For example, using the AUX reserved word can demonstrate this issue.
Recommendations For Cherokee Web Server version 0.5.4, consider restricting access to the server to prevent remote attackers from exploiting this issue until a patch is available. As a temporary workaround, avoid using MS-DOS reserved words in URIs to minimize the risk of daemon crashes.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2009-4587

Affected Products

Cherokee Web Server