5
CVSSv2

CVE-2015-1548

Published: 10/02/2015 Updated: 22/12/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

mini_httpd 1.21 and previous versions allows remote malicious users to obtain sensitive information from process memory via an HTTP request with a long protocol string, which triggers an incorrect response size calculation and an out-of-bounds read.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

acme mini httpd

Vendor Advisories

Debian Bug report logs - #778925 CVE-2015-1548 Package: mini-httpd; Maintainer for mini-httpd is Debian QA Group <packages@qadebianorg>; Source for mini-httpd is src:mini-httpd (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sat, 21 Feb 2015 20:57:06 UTC Severity: grave Tags: security ...