Cherokee web server before 0.2.7 does not properly drop root privileges after binding to port 80, which could allow remote attackers to gain privileges via other vulnerabilities.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cherokee_httpd | Cherokee | 0.1 (including) | 0.1 (including) |
Cherokee_httpd | Cherokee | 0.1.5 (including) | 0.1.5 (including) |
Cherokee_httpd | Cherokee | 0.1.6 (including) | 0.1.6 (including) |
Cherokee_httpd | Cherokee | 0.2 (including) | 0.2 (including) |
Cherokee_httpd | Cherokee | 0.2.5 (including) | 0.2.5 (including) |
Cherokee_httpd | Cherokee | 0.2.6 (including) | 0.2.6 (including) |