thttpd tdate_parse() Stack Overflow...

- AV AC AU C I A
发布: 1999-11-10
修订: 2025-04-13

The thttpd web server (versions 1.90a to 2.04) doesn't do proper bounds checking in the date parsing function tdate_parse(). By overflowing a static buffer in tdate_parse() an attacker could remotely execute commands on the thttpd host with the permissions of thttpd. The buffer overflow occurs when a HTTP GET request is made with an overlong "If-Modified-Since" header(approx. 1300+) characters.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息