Vulnerability Description
Buffer overflows in GazTek ghttpd 1.4 allows a remote attacker to execute arbitrary code via long arguments that are passed to (1) the Log function in util.c, or (2) serveconnection in protocol.c.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gaztek | Ghttp | 1.4 |
References
- http://marc.info/?l=bugtraq&m=99279182704674&w=2
- http://marc.info/?l=bugtraq&m=99406263214417&w=2
- http://www.securityfocus.com/bid/2879ExploitVendor Advisory
- http://www.securityfocus.com/bid/2965
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6702
- http://marc.info/?l=bugtraq&m=99279182704674&w=2
- http://marc.info/?l=bugtraq&m=99406263214417&w=2
- http://www.securityfocus.com/bid/2879ExploitVendor Advisory
- http://www.securityfocus.com/bid/2965
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6702
FAQ
What is CVE-2001-0820?
CVE-2001-0820 is a vulnerability with a CVSS score of 7.5 (HIGH). Buffer overflows in GazTek ghttpd 1.4 allows a remote attacker to execute arbitrary code via long arguments that are passed to (1) the Log function in util.c, or (2) serveconnection in protocol.c.
How severe is CVE-2001-0820?
CVE-2001-0820 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-0820?
Check the references section above for vendor advisories and patch information. Affected products include: Gaztek Ghttp.