Cherokee 0.4.27 to 1.2.104 is affected by a denial of service due to a NULL pointer dereferences. A remote unauthenticated attacker can crash the server by sending an HTTP request to protected resources using a malformed Authorization header that is mishandled during a cherokeebufferadd call within cherokeevalidatorparsebasic or cherokeevalidatorparsedigest.
{
"cpe": "cpe:2.3:a:cherokee-project:cherokee:*:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "0.4.27"
},
{
"last_affected": "1.2.104"
}
]
}