CVE-2014-5015: Eterna Bozohttpd
Medium severity, CVSS 5.0. EPSS: 1.7% chance of exploitation in the next 30 days.
bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrictions, which allows remote attackers to bypass the HTTP authentication scheme and access restrictions via a long path.
Affected products
- Eterna Bozohttpd: up to and including 20140201; version 19990519 only; version 20000421 only; version 20000426 only; version 20000427 only; version 20000815 only; …
- Netbsd Netbsd: version 5.1 only; version 5.2 only; version 6.0 only; version 6.1 only
Published 2014-07-24. Last modified 2026-06-17.