Logo
vulnerabilityCVE-2020-12845
Name
CVE-2020-12845
Source
NVD ( link)Debian ( link)
Description
Cherokee 0.4.27 to 1.2.104 is affected by a denial of service due to a NULL pointer dereferences. A remote unauthenticated attacker can crash the server by sending an HTTP request to protected resources using a malformed Authorization header that is mishandled during a cherokee_buffer_add call within cherokee_validator_parse_basic or cherokee_validator_parse_digest.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
cherokee
Patched

Vulnerability Ratings#


7.5
CVSSv31
5
CVSSv2

Others affected component#


Name
Project
Project Version
Version
Status
yocto
scarthgap
1.2.104+git
Not Affected

Resolved with patches#


cherokee (yocto:kirkstone)

#
Title
Author
Resolve
1
Fix CVE-2020-12845 (#1243)
Stefan de Konink <stefan@konink.de>
CVE-2020-12845