CVE-2019-11072

CVE-2019-11072

lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a malicious HTTP GET request, as demonstrated by mishandling of /%2F? in burl_normalize_2F_to_slash_fix in burl.c.

Source: CVE-2019-11072

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다