CVE-2012-5641: Path Traversal
Directory traversal vulnerability in the partition2 function in mochiwebutil.erl in MochiWeb before 2.4.0, as used in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1, allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the default URI.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5641?
CVE-2012-5641 is rated as a medium severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2012-5641?
To fix CVE-2012-5641, upgrade to MochiWeb version 2.4.0 or later and ensure your Apache CouchDB is updated to versions 1.0.4, 1.1.2, or 1.2.1 or higher.
What software is affected by CVE-2012-5641?
CVE-2012-5641 affects MochiWeb versions prior to 2.4.0 and Apache CouchDB versions before 1.0.4, along with specific earlier versions.
What types of attacks can exploit CVE-2012-5641?
CVE-2012-5641 can be exploited through directory traversal attacks, allowing remote attackers to access arbitrary files on the server.
Is CVE-2012-5641 an exploit that requires authentication?
No, CVE-2012-5641 does not require authentication, making it potentially more dangerous for vulnerable setups.