CVE-2018-16789
By sending a crafted multipart/form-data HTTP request, an attacker could exploit this to force shellinaboxd into an infinite loop, exhausting available CPU resources and taking the service down.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.99%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
libhttp/url.c in shellinabox through 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a crafted multipart/form-data HTTP request, an attacker could exploit this to force shellinaboxd into an infinite loop, exhausting available CPU resources and taking the service down.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 5.99% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-835
- Affected
- shellinabox project/shellinabox
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/149978/Shell-In-A-Box-2.2.0-Denial-Of-Service.htmlExploit, Patch, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2018/Oct/50Exploit, Mailing List, Patch, Third Party Advisory
- https://code.google.com/archive/p/shellinabox/issuesThird Party Advisory
- https://github.com/shellinabox/shellinabox/commit/4f0ecc31ac6f985e0dd3f5a52cbfc0e9251f6361Patch, Third Party Advisory
- http://packetstormsecurity.com/files/149978/Shell-In-A-Box-2.2.0-Denial-Of-Service.htmlExploit, Patch, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2018/Oct/50Exploit, Mailing List, Patch, Third Party Advisory
- https://code.google.com/archive/p/shellinabox/issuesThird Party Advisory
- https://github.com/shellinabox/shellinabox/commit/4f0ecc31ac6f985e0dd3f5a52cbfc0e9251f6361Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.