NULL pointer dereference in Cherokee webserver - CVE-2020-12845
Published: July 28, 2020 / Updated: December 28, 2020
Cherokee webserver
Cherokee-project
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in cherokee_validator_parse_basic or cherokee_validator_parse_digest. A remote attacker can send a specially crafted HTTP request and perform a denial of service (DoS) attack.