CVE-2014-9707: Buffer Overflow
EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remote attackers to conduct directory traversal attacks, cause a denial of service (heap-based buffer overflow and crash), or possibly execute arbitrary code via a crafted URI.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9707?
CVE-2014-9707 has a high severity rating due to the potential for remote code execution and denial of service attacks.
How do I fix CVE-2014-9707?
To fix CVE-2014-9707, update to a patched version of EmbedThis GoAhead that addresses the directory traversal vulnerability.
What versions are affected by CVE-2014-9707?
CVE-2014-9707 affects EmbedThis GoAhead versions 3.0.0 through 3.4.1.
What type of attacks can be executed using CVE-2014-9707?
CVE-2014-9707 can be exploited for directory traversal attacks, heap-based buffer overflows, and potentially arbitrary code execution.
Is CVE-2014-9707 still an active threat?
CVE-2014-9707 remains a relevant threat if affected versions are still in use and have not been secured.