UBUNTU-CVE-2014-5015

Source
https://ubuntu.com/security/CVE-2014-5015
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-5015.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2014-5015
Upstream
  • CVE-2014-5015
Published
2014-07-24T14:55:00Z
Modified
2025-07-16T08:11:07.000603Z
Severity
  • Ubuntu - medium
Summary
[none]
Details

bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrictions, which allows remote attackers to bypass the HTTP authentication scheme and access restrictions via a long path.

References

Affected packages

Ubuntu:14.04:LTS / bozohttpd

Package

Name
bozohttpd
Purl
pkg:deb/ubuntu/bozohttpd@20111118-1+deb7u1build0.14.04.1?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20111118-1+deb7u1build0.14.04.1

Affected versions

Other
20111118-1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "20111118-1+deb7u1build0.14.04.1",
            "binary_name": "bozohttpd"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-5015.json"