bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrictions, which allows remote attackers to bypass the HTTP authentication scheme and access restrictions via a long path.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-490-1 | bozohttpd security update |
![]() |
EUVD-2014-4914 | bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrictions, which allows remote attackers to bypass the HTTP authentication scheme and access restrictions via a long path. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: debian
Published:
Updated: 2024-08-06T11:34:37.205Z
Reserved: 2014-07-18T00:00:00
Link: CVE-2014-5015

No data.

Status : Deferred
Published: 2014-07-24T14:55:09.583
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-5015

No data.

No data.