CVE-2020-13432: High severity hfs http file server vulnerability
rejetto HFS (aka HTTP File Server) v2.3m Build #300, when virtual files or folders are used, allows remote attackers to trigger an invalid-pointer write access violation via concurrent HTTP requests with a long URI or long HTTP headers.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-13432?
CVE-2020-13432 is considered a high severity vulnerability due to the potential for remote denial-of-service attacks.
How do I fix CVE-2020-13432?
To mitigate CVE-2020-13432, consider upgrading to a patched version of Rejetto HFS or implementing network-level protections against malformed HTTP requests.
What versions of Rejetto HFS are affected by CVE-2020-13432?
CVE-2020-13432 affects Rejetto HFS version 2.3m Build #300.
What type of vulnerability is CVE-2020-13432?
CVE-2020-13432 is a remote code execution vulnerability that can lead to an invalid-pointer write access violation.
Can CVE-2020-13432 be exploited remotely?
Yes, CVE-2020-13432 can be exploited remotely through concurrent HTTP requests.