CVE-2009-4491: Input Validation
thttpd 2.25b0 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4491?
CVE-2009-4491 is classified as a medium severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2009-4491?
To fix CVE-2009-4491, update to a patched version of thttpd that sanitizes log file entries.
What are the potential impacts of exploiting CVE-2009-4491?
Exploiting CVE-2009-4491 could allow attackers to execute arbitrary commands or overwrite files.
Is thttpd 2.25-b the only affected version for CVE-2009-4491?
Yes, thttpd 2.25-b is specifically the affected version for CVE-2009-4491.
How can attackers exploit CVE-2009-4491?
Attackers can exploit CVE-2009-4491 by sending crafted HTTP requests that include non-printable characters.