[openbsd-cvs] 20170131 cvs.openbsd.org: srcmailing list
http://marc.info/?l=openbsd-cvs&m=148587359420912&w=2 CVE-2017-5850
HIGH
OpenBSD HTTPd < 6.0 - Memory Exhaustion Denial of Service
Record summary
CVE-2017-5850 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
httpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for a large file using an HTTP Range header.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBOpenBSD HTTPd < 6.0 - Memory Exhaustion Denial of ServiceExploitDB exploitby PierreKimSecNot analyzed1 file
References
12packetstormsecurity.com
http://packetstormsecurity.com/files/140944/OpenBSD-HTTP-Server-6.0-Denial-Of-Service.html 20170206 Remote DoS against OpenBSD http server (up to 6.0)mailing list
http://seclists.org/fulldisclosure/2017/Feb/15 [oss-security] 20170202 Re: CVE requests: OpenBSD httpd - 2 DoSmailing list
http://www.openwall.com/lists/oss-security/2017/02/02/6 95997vdb entry
http://www.securityfocus.com/bid/95997 1037758vdb entry
http://www.securitytracker.com/id/1037758 ftp.openbsd.orgConfirmation
https://ftp.openbsd.org/pub/OpenBSD/patches/5.9/common/034_httpd.patch.sig ftp.openbsd.orgConfirmation
https://ftp.openbsd.org/pub/OpenBSD/patches/6.0/common/017_httpd.patch.sig github.comConfirmation
https://github.com/openbsd/src/commit/142cfc82b932bc211218fbd7bdda8c7ce83f19df nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-5850 pierrekim.github.io
https://pierrekim.github.io/blog/2017-02-07-openbsd-httpd-CVE-2017-5850.html 41278exploit
https://www.exploit-db.com/exploits/41278