CVE-2004-1097: Critical severity Cherokee Cherokee HTTPD vulnerability
Format string vulnerability in the cherokeeloggerncsawritestring function in Cherokee 0.4.17 and earlier, when authenticating via authpam, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via format string specifiers in the URL.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1097?
CVE-2004-1097 is classified as a high severity vulnerability that can lead to denial of service and potential arbitrary code execution.
How do I fix CVE-2004-1097?
To fix CVE-2004-1097, upgrade Cherokee to a version later than 0.4.17.
What types of attacks can exploit CVE-2004-1097?
CVE-2004-1097 can be exploited by remote attackers using format string specifiers in the URL to crash the application or execute arbitrary code.
Which versions of Cherokee are affected by CVE-2004-1097?
CVE-2004-1097 affects Cherokee versions 0.4.17 and earlier, as well as other specific older versions.
What component of Cherokee is vulnerable in CVE-2004-1097?
The vulnerability in CVE-2004-1097 is located in the cherokee_logger_ncsa_write_string function when using auth_pam for authentication.