First published: Tue Nov 16 1999(Updated: )
Buffer overflow in thttpd HTTP server before 2.04-31 allows remote attackers to execute arbitrary commands via a long date string, which is not properly handled by the tdate_parse function.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Thttpd Http Server | <=2.04 | |
Thttpd Http Server | <=2.04.31 | |
Thttpd Http Server | =1.90a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1457 is considered to have a high severity due to the potential for remote code execution.
To fix CVE-1999-1457, update the thttpd HTTP server to version 2.04.31 or later.
CVE-1999-1457 affects thttpd HTTP server versions prior to 2.04.31 and the specific 1.90a version.
Yes, CVE-1999-1457 can be exploited remotely by sending a specially crafted long date string.
If exploited, CVE-1999-1457 can lead to arbitrary command execution on the affected server.