CVE-2014-5015 Information

Description

bozotic HTTP server (aka bozohttpd) before 20140708 as used in NetBSD truncates paths when checking .htpasswd restrictions which allows remote attackers to bypass the HTTP authentication scheme and access restrictions via a long path.

Reference

ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2014-007.txt.asc http://seclists.org/oss-sec/2014/q3/180 http://www.eterna.com.au/bozohttpd/ http://www.eterna.com.au/bozohttpd/CHANGES http://www.osvdb.org/109283 http://www.securityfocus.com/bid/68752 https://exchange.xforce.ibmcloud.com/vulnerabilities/94751

Share on: