Logo
componentshellinabox
Name
shellinabox
Version
2.20
Type
library
Description
-
Licenses
GPL-2.0 with OpenSSL exception
PURL
-
CPE
cpe:2.3:a:shellinabox_project:shellinabox:2.20:-:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
2.20

Patches#


#
Title
Author
Resolve
1
Makefile: disable always building statically
Olivier Singla <olivier.singla@gmail.com>
2
fix for broken multipart/form-data
irsl <irsl@users.noreply.github.com>
CVE-2018-16789

Vulnerabilities#


Name
Analysis
Description
Patched
libhttp/url.c in shellinabox through 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a crafted multipart/form-data HTTP request, an attacker could exploit this to force shellinaboxd into an infinite loop, exhausting available CPU resources and taking the service down.