Description
In Cherokee through 1.2.104, remote attackers can trigger an out-of-bounds write in cherokee_handler_cgi_add_env_pair in handler_cgi.c by sending many request headers, as demonstrated by a GET request with many "Host: 127.0.0.1" headers.
Remediation
References
Related Vulnerabilities
MySQL CVE-2015-2576 Vulnerability (CVE-2015-2576)
MySQL CVE-2021-2028 Vulnerability (CVE-2021-2028)
Django Incorrect Default Permissions Vulnerability (CVE-2020-24583)
Claroline Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2008-3262)
WordPress Plugin ShareThis Dashboard for Google Analytics Cross-Site Scripting (2.5.1)