Back to search
CVE-2011-2900
Published: Aug 5, 2011
Modified: Aug 6, 2024
PUBLISHED
Description
Stack-based buffer overflow in the (1) put_dir function in mongoose.c in Mongoose 3.0, (2) put_dir function in yasslEWS.c in yaSSL Embedded Web Server (yasslEWS) 0.2, and (3) _shttpd_put_dir function in io_dir.c in Simple HTTPD (shttpd) 1.42 allows remote attackers to execute arbitrary code via an HTTP PUT request, as exploited in the wild in 2011.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
FEDORA-2011-11823
vendor-advisory
x_refsource_FEDORA
48980
vdb-entry
x_refsource_BID
45464
third-party-advisory
x_refsource_SECUNIA
45902
third-party-advisory
x_refsource_SECUNIA
FEDORA-2011-11825
vendor-advisory
x_refsource_FEDORA
mongoose-put-bo(68991)
vdb-entry
x_refsource_XF
[oss-security] 20110803 CVE id request: shttpd/mongoose/yassl embedded webserver
mailing-list
x_refsource_MLIST
8337
third-party-advisory
x_refsource_SREASON
FEDORA-2011-11636
vendor-advisory
x_refsource_FEDORA
[oss-security] 20110803 Re: CVE id request: shttpd/mongoose/yassl embedded webserver
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now