CVE-2023-27371
published 2023-02-28CVE-2023-27371: GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data boundary in the postprocessor.c…
PriorityP427medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
1.24%
65.7th percentile
GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data boundary in the postprocessor.c MHD_create_post_processor() method. This allows an attacker to remotely send a malicious HTTP POST packet that includes one or more '\0' bytes in a multipart/form-data boundary field, which - assuming a specific heap layout - will result in an out-of-bounds read and a crash in the find_boundary() function.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libmicrohttpd | < libmicrohttpd 0.9.75-6 (bookworm) | libmicrohttpd 0.9.75-6 (bookworm) |
| gnu | libmicrohttpd | < 0.9.76 | 0.9.76 |
| gnu | libmicrohttpd | >= 0 < 0.9.72-2+deb11u1 | 0.9.72-2+deb11u1 |
| gnu | libmicrohttpd | >= 0 < 0.9.75-6 | 0.9.75-6 |
| gnu | libmicrohttpd | >= 0 < 0.9.75-6 | 0.9.75-6 |
| gnu | libmicrohttpd | >= 0 < 0.9.75-6 | 0.9.75-6 |
| msrc | cbl2_libmicrohttpd_0.9.76-1_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_msrc5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x2hm-ghg4-c67m: GNU libmicrohttpd before 0
ghsa_unreviewed·2023-02-28
CVE-2023-27371 [HIGH] CWE-125 GHSA-x2hm-ghg4-c67m: GNU libmicrohttpd before 0
GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data boundary in the postprocessor.c MHD_create_post_processor() method. This allows an attacker to remotely send a malicious HTTP POST packet that includes one or more '\0' bytes in a multipart/form-data boundary field, which - assuming a specific heap layout - will result in an out-of-bounds read and a crash in the find_boundary() function.
OSV
CVE-2023-27371: GNU libmicrohttpd before 0
osv·2023-02-28·CVSS 5.9
CVE-2023-27371 [MEDIUM] CVE-2023-27371: GNU libmicrohttpd before 0
GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data boundary in the postprocessor.c MHD_create_post_processor() method. This allows an attacker to remotely send a malicious HTTP POST packet that includes one or more '\0' bytes in a multipart/form-data boundary field, which - assuming a specific heap layout - will result in an out-of-bounds read and a crash in the find_boundary() function.
Red Hat
libmicrohttpd: remote DoS
vendor_redhat·2023-02-28·CVSS 5.9
CVE-2023-27371 [MEDIUM] CWE-125 libmicrohttpd: remote DoS
libmicrohttpd: remote DoS
GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data boundary in the postprocessor.c MHD_create_post_processor() method. This allows an attacker to remotely send a malicious HTTP POST packet that includes one or more '\0' bytes in a multipart/form-data boundary field, which - assuming a specific heap layout - will result in an out-of-bounds read and a crash in the find_boundary() function.
An out-of-bounds flaw was found in GNU's libmicrohttpd due to improper parsing of a multipart/form-data boundary in the MHD_create_post_processor() method in postprocessor.c. This flaw allows an attacker to remotely send a malicious HTTP POST packet that includes one or more ‘\0’ bytes in a multipart/form-data b
Microsoft
GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data boundary in the postprocessor.c MHD_create_post_processor() method. This allows a
vendor_msrc·2023-02-14·CVSS 5.9
CVE-2023-27371 [MEDIUM] CWE-125 GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data boundary in the postprocessor.c MHD_create_post_processor() method. This allows a
GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data boundary in the postprocessor.c MHD_create_post_processor() method. This allows an attacker to remotely send a malicious HTTP POST packet that includes one or more '\0' bytes in a multipart/form-data boundary field which - assuming a specific heap layout - will result in an out-of-bounds read and a crash in the find_boundary() function.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source librar
Debian
CVE-2023-27371: libmicrohttpd - GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to imp...
vendor_debian·2023·CVSS 5.9
CVE-2023-27371 [MEDIUM] CVE-2023-27371: libmicrohttpd - GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to imp...
GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data boundary in the postprocessor.c MHD_create_post_processor() method. This allows an attacker to remotely send a malicious HTTP POST packet that includes one or more '\0' bytes in a multipart/form-data boundary field, which - assuming a specific heap layout - will result in an out-of-bounds read and a crash in the find_boundary() function.
Scope: local
bookworm: resolved (fixed in 0.9.75-6)
bullseye: resolved (fixed in 0.9.72-2+deb11u1)
forky: resolved (fixed in 0.9.75-6)
sid: resolved (fixed in 0.9.75-6)
trixie: resolved (fixed in 0.9.75-6)
No detection rules found.
No public exploits indexed.
https://git.gnunet.org/libmicrohttpd.git/commit/?id=6d6846e20bfdf4b3eb1b592c97520a532f724238https://github.com/0xhebi/CVEs/tree/main/GNU%20Libmicrohttpdhttps://lists.debian.org/debian-lts-announce/2023/03/msg00029.htmlhttps://lists.gnu.org/archive/html/libmicrohttpd/2023-02/msg00000.htmlhttps://git.gnunet.org/libmicrohttpd.git/commit/?id=6d6846e20bfdf4b3eb1b592c97520a532f724238https://github.com/0xhebi/CVEs/tree/main/GNU%20Libmicrohttpdhttps://lists.debian.org/debian-lts-announce/2023/03/msg00029.htmlhttps://lists.gnu.org/archive/html/libmicrohttpd/2023-02/msg00000.html
2023-02-28
Published