VDB

CVE-2009-4490

CVE-2009-4490 PUBLISHED

mini_httpd 1.19 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.

EPSS 4.11% · 88.8th percentile

Risk Scores

EPSS Score
4.11%
88.8th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSmini-httpd0, 1.30-2
Ubuntu:24.04:LTSmini-httpd1.30-3, 0, 1.30-7
Ubuntu:Pro:14.04:LTSmini-httpd0, 1.19-9.3, *
Ubuntu:Pro:16.04:LTSmini-httpd1.19-9.3, 1.23-1, 0
Ubuntu:Pro:18.04:LTSmini-httpd1.23-1.2build1, 0, 1.23-1.2
Ubuntu:25.10mini-httpd0, 1.30-13, 1.30-12
Ubuntu:22.04:LTSmini-httpd0, 1.30-2build1, 1.30-2

Timeline

  • Jan 13, 2010 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • May 25, 2023 EPSS Score
  • Jul 17, 2023 EPSS Score
  • Sep 7, 2023 EPSS Score
  • Dec 22, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›