Candidate: CVE-2018-18778 PublicDate: 2018-10-29 12:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18778 http://www.acme.com/software/mini_httpd/ Description: ACME mini_httpd before 1.30 lets remote users read arbitrary files. Ubuntu-Description: It was discovered that ACME mini_httpd did not properly handle HTTP GET requests with empty headers. A remote attacker could use this vulnerability to read arbitrary files. Notes: Bugs: Priority: high Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N [6.5 MEDIUM] Patches_mini-httpd: upstream_mini-httpd: released (1.30-0.1) precise/esm_mini-httpd: DNE trusty_mini-httpd: ignored (reached end-of-life) trusty/esm_mini-httpd: DNE (trusty was needed) xenial_mini-httpd: ignored (end of standard support, was needed) bionic_mini-httpd: needed cosmic_mini-httpd: ignored (reached end-of-life) disco_mini-httpd: not-affected (1.30-0.2) eoan_mini-httpd: not-affected (1.30-2) focal_mini-httpd: not-affected (1.30-2) groovy_mini-httpd: not-affected (1.30-2) hirsute_mini-httpd: not-affected (1.30-2) impish_mini-httpd: not-affected (1.30-2) jammy_mini-httpd: not-affected (1.30-2) devel_mini-httpd: not-affected (1.30-2)