Logo
vulnerabilityCVE-2021-26843
Name
CVE-2021-26843
Source
NVD ( link)Debian ( link)
Description
An issue was discovered in sthttpd through 2.27.1. On systems where the strcpy function is implemented with memcpy, the de_dotdot function may cause a Denial-of-Service (daemon crash) due to overlapping memory ranges being passed to memcpy. This can triggered with an HTTP GET request for a crafted filename. NOTE: this is similar to CVE-2017-10671, but occurs in a different part of the de_dotdot function.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
sthttpd
Exploitable

Vulnerability Ratings#


7.5
CVSSv31
5
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
yocto
kirkstone
2.27.1
Exploitable
yocto
scarthgap
2.27.1
Exploitable