Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

thttpd/mini_httpd Virtual Hosting File Disclosure

High

Synopsis

The remote host is vulnerable to a flaw that allows attackers to retrieve sensitive files or data.

Description

The remote host is running a vulnerable version of Acme mini_httpd. It is reported that versions prior 1.18 are prone to an issue that may permit an attacker to access arbitrary files on the vulnerable web server when virtual hosting is enabled. In a chrooted environment, this may only disclose directories under the chroot.

Solution

Upgrade or patch according to vendor recommendations.