Heap-based Buffer Overflow in the de_dotdot function in libhttpd.c in sthttpd before 2.27.1 allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a crafted filename.
"2026-04-11T03:56:49Z"
[
{
"id": "CVE-2017-10671-29b3bc57",
"target": {
"file": "src/libhttpd.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"31622178336681743686303755056012371620",
"214863769995483382969825078872332022510",
"62992683728358547129517580158816060754",
"310969007111829704107366180939192588527"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://github.com/blueness/sthttpd/commit/c0dc63a49d8605649f1d8e4a96c9b468b0bff660",
"signature_version": "v1"
},
{
"id": "CVE-2017-10671-a63e0fd5",
"target": {
"file": "src/libhttpd.c",
"function": "de_dotdot"
},
"deprecated": false,
"digest": {
"function_hash": "64795455695707646306100003558705630774",
"length": 1022.0
},
"signature_type": "Function",
"source": "https://github.com/blueness/sthttpd/commit/c0dc63a49d8605649f1d8e4a96c9b468b0bff660",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-10671.json"