CVE-2011-2900

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
05/08/2011
Last modified:
11/04/2025

Description

Stack-based buffer overflow in the (1) put_dir function in mongoose.c in Mongoose 3.0, (2) put_dir function in yasslEWS.c in yaSSL Embedded Web Server (yasslEWS) 0.2, and (3) _shttpd_put_dir function in io_dir.c in Simple HTTPD (shttpd) 1.42 allows remote attackers to execute arbitrary code via an HTTP PUT request, as exploited in the wild in 2011.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:shttpd:shttpd:1.42:*:*:*:*:*:*:*
cpe:2.3:a:valenok:mongoose:3.0:*:*:*:*:*:*:*
cpe:2.3:a:yassl:yasslews:0.2:*:*:*:*:*:*:*