thttpd 2.04 If-Modified-Since Header Remote Buffer Overflow

This script is Copyright (C) 1999-2011 Tenable Network Security, Inc.


Synopsis :

The remote web server is affected by a buffer overflow
vulnerability.

Description :

It is possible to make the remote thttpd server execute
arbitrary code by sending a request like :

GET / HTTP/1.0
If-Modified-Since: AAA[...]AAAA

An attacker may use this to gain control on your computer.

Solution :

If you are using thttpd, upgrade to version 2.05.
If you are not, then contact your vendor and ask for
a patch, or change your web server

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 7.4
(CVSS2#E:U/RL:OF/RC:ND)
Public Exploit Available : false

Family: Web Servers

Nessus Plugin ID: 10285 ()

Bugtraq ID: 1248

CVE ID: CVE-2000-0359