CVE-2012-5641
18.03.2014, 17:02
Directory traversal vulnerability in the partition2 function in mochiweb_util.erl in MochiWeb before 2.4.0, as used in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1, allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the default URI.
Vendor | Product | Version |
---|---|---|
apache | couchdb | 𝑥 ≤ 1.0.3 |
apache | couchdb | 1.0.0 |
apache | couchdb | 1.0.1 |
apache | couchdb | 1.0.2 |
apache | couchdb | 1.1.0 |
apache | couchdb | 1.1.1 |
apache | couchdb | 1.2.0 |
mochiweb_project | mochiweb | 𝑥 ≤ 2.3.2 |
mochiweb_project | mochiweb | 2.1.0 |
mochiweb_project | mochiweb | 2.2.0 |
mochiweb_project | mochiweb | 2.2.1 |
mochiweb_project | mochiweb | 2.3.0 |
mochiweb_project | mochiweb | 2.3.1 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References