---
cve: "CVE-2017-10671"
severity: "LOW"
cvss: 3.1
epss: "1.5%"
vendor: "n/a"
kev: false
exploited: false
published: "2017-06-29 08:29:00"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-11T15:22:35+02:00"
---

# CVE-2017-10671

> 3.1 LOW · 🧪 PoC

## Beschreibung

Heap-based Buffer Overflow in the de_dotdot function in libhttpd.c in sthttpd before 2.27.1 allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a crafted filename.

## Patch verfügbar (OSV)

- 2845bf5bff2b820d2336c8c8061cbfc5f271e720 (Commit)
- c0dc63a49d8605649f1d8e4a96c9b468b0bff660 (Commit)

## Referenzen

- <http://www.openwall.com/lists/oss-security/2017/06/15/9>
- <https://github.com/blueness/sthttpd/releases/tag/v2.27.1>
- <https://github.com/blueness/sthttpd/commit/c0dc63a49d8605649f1d8e4a96c9b468b0bff660>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2017-10671) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
