CVE-2003-0899: Buffer Overflow
Published Oct 30, 2003
·Updated
Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "<" and ">" sequences.
Affected Software
8 affected components
debian/thttpd
Acme Labs thttpd=2.21
Acme Labs thttpd=2.21b
Acme Labs thttpd=2.23b1
Acme Labs thttpd=2.22
ACME Thttpd>=2.21<2.23
ACME Thttpd=2.23
ACME Thttpd=2.23-b1
Remediation
Patch Available
Patch Available
Event History
Oct 30, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Nov 3, 2003
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
How can attackers exploit CVE-2003-0899?
Attackers can exploit CVE-2003-0899 by sending specially crafted requests with '<' or '>' characters to execute arbitrary code on the affected server.