USN-4848-1: mini_httpd vulnerability
15 March 2021
mini_httpd could be made to expose sensitive information over the network.
Releases
Packages
- mini-httpd - Small HTTP server
Details
It was discovered that ACME mini_httpd did not properly handle HTTP GET
requests with empty headers. A remote attacker could use this vulnerability
to read arbitrary files.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 18.04
-
mini-httpd
-
1.23-1.2ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 16.04
-
mini-httpd
-
1.23-1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 14.04
-
mini-httpd
-
1.19-9.3ubuntu0.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.