CVE-2016-9564: Input Validation
Published Nov 30, 2016
·Updated
Buffer overflow in sendredirect() in Boa Webserver 0.92r allows remote attackers to DoS via an HTTP GET request requesting a long URI with only '/' and '.' characters.
Affected Software
1 affected component
Boa Boa=0.92r
Event History
Nov 30, 2016
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-9564?
CVE-2016-9564 is categorized as a high-severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2016-9564?
To mitigate CVE-2016-9564, you should upgrade the Boa Webserver to a version that does not contain this vulnerability.
3
What type of attack does CVE-2016-9564 allow?
CVE-2016-9564 allows remote attackers to cause denial of service through a crafted HTTP GET request.
4
Which versions of Boa Webserver are affected by CVE-2016-9564?
CVE-2016-9564 specifically affects Boa Webserver version 0.92r.
5
What kind of exploit is CVE-2016-9564 related to?
CVE-2016-9564 is related to a buffer overflow exploit triggered by long URIs composed of '/' and '.' characters.