GNU libmicrohttpd 0.9.70

CPE Details

GNU libmicrohttpd 0.9.70
0.9.70
2021-05-05
13h18 +00:00
2021-05-10
14h00 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:gnu:libmicrohttpd:0.9.70:*:*:*:*:*:*:*

Informations

Vendor

gnu

Product

libmicrohttpd

Version

0.9.70

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-27371 2023-02-28 00h00 +00:00 GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data boundary in the postprocessor.c MHD_create_post_processor() method. This allows an attacker to remotely send a malicious HTTP POST packet that includes one or more '\0' bytes in a multipart/form-data boundary field, which - assuming a specific heap layout - will result in an out-of-bounds read and a crash in the find_boundary() function.
5.9
Medium
CVE-2021-3466 2021-03-24 23h00 +00:00 A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attacker to write arbitrary data in an application that uses libmicrohttpd. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Only version 0.9.70 is vulnerable.
9.8
Critical