CVE-2021-3466
published 2021-03-25CVE-2021-3466: A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attacker to…
PriorityP264critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
8.74%
94.5th percentile
A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attacker to write arbitrary data in an application that uses libmicrohttpd. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Only version 0.9.70 is vulnerable.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libmicrohttpd | < libmicrohttpd 0.9.71-1 (bookworm) | libmicrohttpd 0.9.71-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | libmicrohttpd | — | — |
| gnu | libmicrohttpd | — | — |
| gnu | libmicrohttpd | >= 0 < 0.9.71-1 | 0.9.71-1 |
| gnu | libmicrohttpd | >= 0 < 0.9.71-1 | 0.9.71-1 |
| gnu | libmicrohttpd | >= 0 < 0.9.71-1 | 0.9.71-1 |
| gnu | libmicrohttpd | >= 0 < 0.9.71-1 | 0.9.71-1 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerable function is `post_process_urlencoded` in libmicrohttpd — monitor for crashes or anomalous POST body processing in applications using this library, specifically on version 0.9.70. ↗
- →Only libmicrohttpd version 0.9.70 is vulnerable; detection/triage should focus exclusively on deployments running this exact version. ↗
- ·Red Hat Enterprise Linux 6, 7, 8, and 9 ship versions of libmicrohttpd that predate the vulnerable code — these platforms are not affected and should be excluded from detection scope. ↗
- ·The vulnerability is fixed in libmicrohttpd 0.9.71; Debian-based systems patched to 0.9.71-1 (bookworm, bullseye, forky, sid, trixie) are no longer vulnerable. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vjm5-89cg-7hj8: A flaw was found in libmicrohttpd in versions before 0
ghsa_unreviewed·2022-05-24
CVE-2021-3466 [CRITICAL] CWE-120 GHSA-vjm5-89cg-7hj8: A flaw was found in libmicrohttpd in versions before 0
A flaw was found in libmicrohttpd in versions before 0.9.71. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attacker to write arbitrary data in an application that uses libmicrohttpd. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
OSV
CVE-2021-3466: A flaw was found in libmicrohttpd
osv·2021-03-25·CVSS 9.8
CVE-2021-3466 [CRITICAL] CVE-2021-3466: A flaw was found in libmicrohttpd
A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attacker to write arbitrary data in an application that uses libmicrohttpd. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Only version 0.9.70 is vulnerable.
Red Hat
libmicrohttpd: Buffer overflow issue in URL parser in the post_process_urlencoded function
vendor_redhat·2021-03-15·CVSS 9.8
CVE-2021-3466 [CRITICAL] CWE-120 libmicrohttpd: Buffer overflow issue in URL parser in the post_process_urlencoded function
libmicrohttpd: Buffer overflow issue in URL parser in the post_process_urlencoded function
A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attacker to write arbitrary data in an application that uses libmicrohttpd. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Only version 0.9.70 is vulnerable.
A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attacker to write arbitrary data in an application that uses libmicrohttpd. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Debian
CVE-2021-3466: libmicrohttpd - A flaw was found in libmicrohttpd. A missing bounds check in the post_process_ur...
vendor_debian·2021·CVSS 9.8
CVE-2021-3466 [CRITICAL] CVE-2021-3466: libmicrohttpd - A flaw was found in libmicrohttpd. A missing bounds check in the post_process_ur...
A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attacker to write arbitrary data in an application that uses libmicrohttpd. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. Only version 0.9.70 is vulnerable.
Scope: local
bookworm: resolved (fixed in 0.9.71-1)
bullseye: resolved (fixed in 0.9.71-1)
forky: resolved (fixed in 0.9.71-1)
sid: resolved (fixed in 0.9.71-1)
trixie: resolved (fixed in 0.9.71-1)
No detection rules found.
No public exploits indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1939127https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4334XJNDJPYQNFE6S3S2KUJJ7TMHYCWL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/75HDMREKITMGPGE62NP7KE62ZJVLETXN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K5NEPVGP3L2CZHLZ4UB44PEILHKPDBOG/https://security.gentoo.org/glsa/202311-08https://bugzilla.redhat.com/show_bug.cgi?id=1939127https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4334XJNDJPYQNFE6S3S2KUJJ7TMHYCWL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/75HDMREKITMGPGE62NP7KE62ZJVLETXN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K5NEPVGP3L2CZHLZ4UB44PEILHKPDBOG/https://security.gentoo.org/glsa/202311-08
2021-03-25
Published