libhttp/url.c in shellinabox up to and including 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a crafted multipart/form-data HTTP request, an attacker could exploit this to force shellinaboxd into an infinite loop, exhausting available CPU resources and taking the service down.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
shellinabox project shellinabox |