CVE Vulnerabilities

CVE-2014-9707

Published: Mar 31, 2015 | Modified: Oct 09, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remote attackers to conduct directory traversal attacks, cause a denial of service (heap-based buffer overflow and crash), or possibly execute arbitrary code via a crafted URI.

Affected Software

Name Vendor Start Version End Version
Goahead Embedthis 3.0.0 (including) 3.0.0 (including)
Goahead Embedthis 3.3.1 (including) 3.3.1 (including)
Goahead Embedthis 3.3.2 (including) 3.3.2 (including)
Goahead Embedthis 3.3.3 (including) 3.3.3 (including)
Goahead Embedthis 3.3.4 (including) 3.3.4 (including)
Goahead Embedthis 3.3.5 (including) 3.3.5 (including)
Goahead Embedthis 3.3.6 (including) 3.3.6 (including)
Goahead Embedthis 3.4.0 (including) 3.4.0 (including)

References