CVE-2009-3663: Critical severity httpdx vulnerability
Format string vulnerability in the hreadrequest function in http.c in httpdx Web Server 1.4 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in the Host header.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3663?
CVE-2009-3663 has a high severity rating due to its potential for causing denial of service or executing arbitrary code.
How do I fix CVE-2009-3663?
To mitigate CVE-2009-3663, upgrade to a version of the httpdx Web Server that is not vulnerable to the format string vulnerability.
What types of attacks can exploit CVE-2009-3663?
CVE-2009-3663 can be exploited through crafted Host header inputs leading to denial of service or arbitrary code execution.
Is there a workaround for CVE-2009-3663?
A potential workaround for CVE-2009-3663 includes filtering or sanitizing Host header inputs.
What software versions are affected by CVE-2009-3663?
CVE-2009-3663 affects the httpdx Web Server version 1.4.