CVE Vulnerabilities

CVE-2014-5015

Published: Jul 24, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrictions, which allows remote attackers to bypass the HTTP authentication scheme and access restrictions via a long path.

Affected Software

NameVendorStart VersionEnd Version
BozohttpdEterna*20140201 (including)
BozohttpdEterna19990519 (including)19990519 (including)
BozohttpdEterna20000421 (including)20000421 (including)
BozohttpdEterna20000426 (including)20000426 (including)
BozohttpdEterna20000427 (including)20000427 (including)
BozohttpdEterna20000815 (including)20000815 (including)
BozohttpdEterna20000825 (including)20000825 (including)
BozohttpdEterna20010610 (including)20010610 (including)
BozohttpdEterna20010812 (including)20010812 (including)
BozohttpdEterna20010922 (including)20010922 (including)
BozohttpdEterna20020710 (including)20020710 (including)
BozohttpdEterna20020730 (including)20020730 (including)
BozohttpdEterna20020803 (including)20020803 (including)
BozohttpdEterna20020804 (including)20020804 (including)
BozohttpdEterna20020823 (including)20020823 (including)
BozohttpdEterna20020913 (including)20020913 (including)
BozohttpdEterna20021106 (including)20021106 (including)
BozohttpdEterna20030313 (including)20030313 (including)
BozohttpdEterna20030409 (including)20030409 (including)
BozohttpdEterna20030626 (including)20030626 (including)
BozohttpdEterna20031005 (including)20031005 (including)
BozohttpdEterna20040218 (including)20040218 (including)
BozohttpdEterna20040808 (including)20040808 (including)
BozohttpdEterna20050410 (including)20050410 (including)
BozohttpdEterna20060517 (including)20060517 (including)
BozohttpdEterna20060710 (including)20060710 (including)
BozohttpdEterna20080303 (including)20080303 (including)
BozohttpdEterna20090417 (including)20090417 (including)
BozohttpdEterna20090522 (including)20090522 (including)
BozohttpdEterna20100509 (including)20100509 (including)
BozohttpdEterna20100512 (including)20100512 (including)
BozohttpdEterna20100617 (including)20100617 (including)
BozohttpdEterna20100621 (including)20100621 (including)
BozohttpdEterna20100920 (including)20100920 (including)
BozohttpdEterna20111118 (including)20111118 (including)
BozohttpdEterna20140102 (including)20140102 (including)
NetbsdNetbsd5.1 (including)5.1 (including)
NetbsdNetbsd5.2 (including)5.2 (including)
NetbsdNetbsd6.0 (including)6.0 (including)
NetbsdNetbsd6.1 (including)6.1 (including)
BozohttpdUbuntulucid*
BozohttpdUbuntuprecise*
BozohttpdUbuntutrusty*
BozohttpdUbuntuupstream*
BozohttpdUbuntuutopic*

References