CVE-2014-5015: Medium severity eterna bozohttpd vulnerability

Published Jul 24, 2014
·
Updated

bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrictions, which allows remote attackers to bypass the HTTP authentication scheme and access restrictions via a long path.

Affected Software

40 affected components
Eterna Bozohttpd<=20140201
Eterna Bozohttpd=19990519
Eterna Bozohttpd=20000421
Eterna Bozohttpd=20000426
Eterna Bozohttpd=20000427
Eterna Bozohttpd=20000815
Eterna Bozohttpd=20000825
Eterna Bozohttpd=20010610
Eterna Bozohttpd=20010812
Eterna Bozohttpd=20010922
Eterna Bozohttpd=20020710
Eterna Bozohttpd=20020730
Eterna Bozohttpd=20020803
Eterna Bozohttpd=20020804
Eterna Bozohttpd=20020823
Eterna Bozohttpd=20020913
Eterna Bozohttpd=20021106
Eterna Bozohttpd=20030313
Eterna Bozohttpd=20030409
Eterna Bozohttpd=20030626
Eterna Bozohttpd=20031005
Eterna Bozohttpd=20040218
Eterna Bozohttpd=20040808
Eterna Bozohttpd=20050410
Eterna Bozohttpd=20060517
Eterna Bozohttpd=20060710
Eterna Bozohttpd=20080303
Eterna Bozohttpd=20090417
Eterna Bozohttpd=20090522
Eterna Bozohttpd=20100509
Eterna Bozohttpd=20100512
Eterna Bozohttpd=20100617
Eterna Bozohttpd=20100621
Eterna Bozohttpd=20100920
Eterna Bozohttpd=20111118
Eterna Bozohttpd=20140102
NetBSD NetBSD=5.1
NetBSD NetBSD=5.2
NetBSD NetBSD=6.0
NetBSD NetBSD=6.1

Remediation

Event History

Jul 24, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2014-5015?

CVE-2014-5015 is considered a moderate severity vulnerability due to its ability to bypass authentication mechanisms.

2

How do I fix CVE-2014-5015?

To fix CVE-2014-5015, update to a version of bozohttpd released after 20140708 where this issue has been addressed.

3

What types of attacks can exploit CVE-2014-5015?

CVE-2014-5015 can be exploited by remote attackers to bypass HTTP authentication and access restricted areas of the server.

4

Which versions of bozohttpd are affected by CVE-2014-5015?

CVE-2014-5015 affects all versions of bozohttpd prior to 20140708.

5

Which platforms are impacted by CVE-2014-5015?

CVE-2014-5015 primarily impacts the bozohttpd server as used in NetBSD.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203