Common vulnerabilities and Exposures (CVE)

Skip to main content

Required CVE Record Information

Description

An issue was discovered in sthttpd through 2.27.1. On systems where the strcpy function is implemented with memcpy, the de_dotdot function may cause a Denial-of-Service (daemon crash) due to overlapping memory ranges being passed to memcpy. This can triggered with an HTTP GET request for a crafted filename. NOTE: this is similar to CVE-2017-10671, but occurs in a different part of the de_dotdot function.

Product Status

Learn more

Information not provided

Updated:

This container includes required additional information provided by the CVE Program for this vulnerability.