THREAT OPS › Threat News › thttpd v2.26 Stack-Based Buffer Overflow in thttpd redirect CGI Program
thttpd v2.26 Stack-Based Buffer Overflow in thttpd redirect CGI Program
<p>Posted by Ron E on Sep 03</p>*Description:*<br /> A stack-based buffer overflow vulnerability exists in the redirect CGI<br /> program distributed with thttpd. The vulnerability is caused by unsafe<br /> string concatenation when constructing redirect URLs using<br /> attacker-controlled CGI environment variables. A remote, unauthenticated<br /> attacker can trigger the vulnerability via a craf
Original source: https://seclists.org/fulldisclosure/2026/Sep/16