VulnerabilityModified
CVE-2014-5015
bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrictions, which allows remote attackers to bypass the HTTP authentication scheme and access restrictions via a long path.
MEDIUM 5.0EPSS 1.74%
Does this matter?
Lower severity and a low EPSS score (1.74%). Track it; it rarely justifies an emergency change on its own.
Description
bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrictions, which allows remote attackers to bypass the HTTP authentication scheme and access restrictions via a long path.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.74% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- eterna/bozohttpd · netbsd/netbsd
- Source
- security@debian.org
References
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2014-007.txt.ascVendor Advisory
- http://seclists.org/oss-sec/2014/q3/180
- http://www.eterna.com.au/bozohttpd/Patch
- http://www.eterna.com.au/bozohttpd/CHANGES
- http://www.osvdb.org/109283
- http://www.securityfocus.com/bid/68752
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94751
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2014-007.txt.ascVendor Advisory
- http://seclists.org/oss-sec/2014/q3/180
- http://www.eterna.com.au/bozohttpd/Patch
- http://www.eterna.com.au/bozohttpd/CHANGES
- http://www.osvdb.org/109283
- http://www.securityfocus.com/bid/68752
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94751
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.