CVE-2009-4587

Publication date 7 January 2010

Last updated 24 July 2024


Ubuntu priority

Description

Cherokee Web Server 0.5.4 allows remote attackers to cause a denial of service (daemon crash) via an MS-DOS reserved word in a URI, as demonstrated by the AUX reserved word.

Read the notes from the security team

Status

Package Ubuntu Release Status
cherokee 9.10 karmic
Not affected
9.04 jaunty
Not affected
8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
6.06 LTS dapper
Not affected

Notes


mdeslaur

PoC: http://xc0re.wordpress.com/2009/10/25/cherokee-web-server-0-5-4-denial-of-service/ windows-specific


Access our resources on patching vulnerabilities