CVE-2001-1496: Buffer Overflow
Published Dec 31, 2001
·Updated
Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of service and possibly execute arbitrary code.
Affected Software
24 affected components
Acme Labs thttpd=1.95
Acme Labs thttpd=2.0
Acme Labs thttpd=2.0.1
Acme Labs thttpd=2.0.2
Acme Labs thttpd=2.0.3
Acme Labs thttpd=2.0.4
Acme Labs thttpd=2.0.5
Acme Labs thttpd=2.0.6
Acme Labs thttpd=2.0.7
Acme Labs thttpd=2.0.8
Acme Labs thttpd=2.0.9
Acme Labs thttpd=2.10
Acme Labs thttpd=2.11
Acme Labs thttpd=2.12
Acme Labs thttpd=2.13
Acme Labs thttpd=2.14
Acme Labs thttpd=2.15
Acme Labs thttpd=2.16
Acme Labs thttpd=2.17
Acme Labs thttpd=2.18
Acme Labs thttpd=2.19
Acme Labs thttpd=2.20
Acme Labs thttpd=2.20b
ACME Thttpd>=1.95<=2.20
Event History
Dec 31, 2001
CVE Published
05:00 AM
Jun 21, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1496?
CVE-2001-1496 has a severity rating that indicates the potential for denial of service and arbitrary code execution.
2
How do I fix CVE-2001-1496?
To fix CVE-2001-1496, update to a secure version of Acme Labs thttpd that is not affected by this vulnerability, such as versions after 2.20.
3
What type of vulnerability is CVE-2001-1496?
CVE-2001-1496 is classified as an off-by-one buffer overflow vulnerability.
4
Which versions of thttpd are affected by CVE-2001-1496?
CVE-2001-1496 affects thttpd versions from 1.95 through 2.20.
5
Can CVE-2001-1496 lead to remote code execution?
Yes, CVE-2001-1496 allows remote attackers to potentially execute arbitrary code.