CVE-2007-6326: Input Validation
Published Dec 13, 2007
·Updated
Sergey Lyubka Simple HTTPD (shttpd) 1.3 on Windows allows remote attackers to cause a denial of service via a request that includes an MS-DOS device name, as demonstrated by the /aux URI.
Affected Software
1 affected component
Sergey Lyubka Simple HTTPD=1.3
Event History
Dec 13, 2007
CVE Published
07:46 PM
Dec 14, 2007
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-6326?
CVE-2007-6326 is classified as a denial of service vulnerability.
2
How do I fix CVE-2007-6326?
To mitigate CVE-2007-6326, upgrade to a version of Simple HTTPD that is not affected by this vulnerability.
3
What versions are affected by CVE-2007-6326?
CVE-2007-6326 affects Simple HTTPD version 1.3 on Windows.
4
What type of attack does CVE-2007-6326 facilitate?
CVE-2007-6326 allows remote attackers to cause a denial of service through specially crafted requests.
5
Who is the vendor associated with CVE-2007-6326?
The vendor associated with CVE-2007-6326 is Sergey Lyubka.