PT-2018-6543 · Acme+2 · Thttpd+3

Alessio Santoru

·

Published

2018-02-06

·

Updated

2025-06-28

·

CVE-2017-17663

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: mini httpd versions prior to 1.28 thttpd versions prior to 2.28
Description: The issue is related to a buffer overflow in the htpasswd implementation, which can be exploited remotely to perform code execution.
Recommendations: For mini httpd versions prior to 1.28, update to version 1.28 or later. For thttpd versions prior to 2.28, update to version 2.28 or later.

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2953
ALT-PU-2021-3120
ALT-PU-2024-14062
CVE-2017-17663
OPENSUSE-SU-2024:11460-1

Affected Products

Alt Linux
Debian
Mini Httpd
Thttpd