Vulnerability Description
Cherokee Web Server 0.5.4 allows remote attackers to cause a denial of service (daemon crash) via an MS-DOS reserved word in a URI, as demonstrated by the AUX reserved word.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cherokee | Cherokee | 0.5.4 |
References
- http://www.securityfocus.com/archive/1/507456/100/0/threaded
- http://www.securityfocus.com/archive/1/507651/100/0/thread
- http://www.securityfocus.com/bid/36814
- http://www.securitytracker.com/id?1023095
- http://xc0re.wordpress.com/2009/10/25/cherokee-web-server-0-5-4-denial-of-servicExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53957
- http://www.securityfocus.com/archive/1/507456/100/0/threaded
- http://www.securityfocus.com/archive/1/507651/100/0/thread
- http://www.securityfocus.com/bid/36814
- http://www.securitytracker.com/id?1023095
- http://xc0re.wordpress.com/2009/10/25/cherokee-web-server-0-5-4-denial-of-servicExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53957
FAQ
What is CVE-2009-4587?
CVE-2009-4587 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Cherokee Web Server 0.5.4 allows remote attackers to cause a denial of service (daemon crash) via an MS-DOS reserved word in a URI, as demonstrated by the AUX reserved word.
How severe is CVE-2009-4587?
CVE-2009-4587 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-4587?
Check the references section above for vendor advisories and patch information. Affected products include: Cherokee Cherokee.