Vulnerability Description
Cherokee Webserver Latest Cherokee Web server Upto Version 1.2.103 (Current stable) is affected by: Buffer Overflow - CWE-120. The impact is: Crash. The component is: Main cherokee command. The attack vector is: Overwrite argv[0] to an insane length with execl. The fixed version is: There's no fix yet.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cherokee-Project | Cherokee Web Server | <= 1.2.103 |
Related Weaknesses (CWE)
References
- https://i.imgur.com/PWCCyir.pngExploitThird Party Advisory
- https://i.imgur.com/PWCCyir.pngExploitThird Party Advisory
FAQ
What is CVE-2019-1010218?
CVE-2019-1010218 is a vulnerability with a CVSS score of 7.5 (HIGH). Cherokee Webserver Latest Cherokee Web server Upto Version 1.2.103 (Current stable) is affected by: Buffer Overflow - CWE-120. The impact is: Crash. The component is: Main cherokee command. The attack...
How severe is CVE-2019-1010218?
CVE-2019-1010218 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-1010218?
Check the references section above for vendor advisories and patch information. Affected products include: Cherokee-Project Cherokee Web Server.