CVE-2012-5640: Null Pointer Dereference
Published Nov 25, 2019
·Updated
thttpd has a local DoS vulnerability via specially-crafted .htpasswd files
Affected Software
2 affected components
debian/thttpd
ACME Thttpd
Event History
Nov 25, 2019
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
DescriptionWeakness
Aug 6, 2024
Data Sourced
via Debian·09:19 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2012-5640?
CVE-2012-5640 is classified as a local Denial of Service (DoS) vulnerability.
2
How does CVE-2012-5640 affect thttpd?
CVE-2012-5640 allows a local attacker to trigger a DoS condition through specially-crafted .htpasswd files.
3
How can I mitigate CVE-2012-5640?
To mitigate CVE-2012-5640, avoid using .htpasswd files that are improperly configured or crafted.
4
Which versions of thttpd are affected by CVE-2012-5640?
CVE-2012-5640 affects the thttpd server versions provided by Acme and Debian.
5
Is there a patch available for CVE-2012-5640?
As of now, specific patches for CVE-2012-5640 should be checked from the software vendor or your distribution package manager.