PT-2010-1406 · Alonso Fernández · Cherokee Web Server
0X90
+1
·
Published
2010-01-07
·
Updated
2018-10-10
·
CVE-2009-4587
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Cherokee Web Server version 0.5.4
Description
The issue allows remote attackers to cause a denial of service, resulting in the daemon crashing. This can be achieved by including an MS-DOS reserved word in a URI. For example, using the AUX reserved word can demonstrate this issue.
Recommendations
For Cherokee Web Server version 0.5.4, consider restricting access to the server to prevent remote attackers from exploiting this issue until a patch is available. As a temporary workaround, avoid using MS-DOS reserved words in URIs to minimize the risk of daemon crashes.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cherokee Web Server