yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2017-10671
Component Overview
Vulnerability Overview
Name
CVE-2017-10671
Source
NVD (
link
)
Debian (
link
)
Description
Heap-based Buffer Overflow in the de_dotdot function in libhttpd.c in sthttpd before 2.27.1 allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a crafted filename.
CWEs
CWE-787
Published Date
Jun 29, 2017
Updated Date
Jun 17, 2026
Workaround
-
Advisories
http://www.openwall.com/lists/oss-security/2017/06/15/9
Mailing List
https://github.com/blueness/sthttpd/commit/c0dc63a49d8605649f1d8e4a96c9b468b0bff660
Issue Tracking
https://github.com/blueness/sthttpd/releases/tag/v2.27.1
Issue Tracking
http://www.openwall.com/lists/oss-security/2017/06/15/9
Mailing List
https://github.com/blueness/sthttpd/commit/c0dc63a49d8605649f1d8e4a96c9b468b0bff660
Issue Tracking
https://github.com/blueness/sthttpd/releases/tag/v2.27.1
Issue Tracking
Analysis
#
Affected Component
Analysis
sthttpd
Not Affected
Vulnerability Ratings
#
7.8
CVSSv31
6.8
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
sthttpd
yocto
kirkstone
2.27.1
Not Affected
sthttpd
yocto
master
2.27.1
Not Affected