Vulnerability record · CVE-2003-0899 · published 3 November 2003
CVE-2003-0899: Acme thttpd vulnerability
Acme · Thttpd
Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "<" and ">" sequences.
Description
Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "<" and ">" sequences.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://marc.info/?l=bugtraq&m=106729188224252&w=2 | ExploitMailing List |
| http://secunia.com/advisories/10092 | Broken LinkPatchVendor Advisory |
| http://www.osvdb.org/2729 | Broken Link |
| http://www.securityfocus.com/bid/8906 | Broken LinkExploitPatchThird Party AdvisoryVDB Entry |
| http://www.texonet.com/advisories/TEXONET-20030908.txt | Broken LinkURL Repurposed |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/13530 | Third Party AdvisoryVDB Entry |
| https://www.debian.org/security/2003/dsa-396 | Broken Link |
| http://marc.info/?l=bugtraq&m=106729188224252&w=2 | ExploitMailing List |
| http://secunia.com/advisories/10092 | Broken LinkPatchVendor Advisory |
| http://www.osvdb.org/2729 | Broken Link |
| http://www.securityfocus.com/bid/8906 | Broken LinkExploitPatchThird Party AdvisoryVDB Entry |
| http://www.texonet.com/advisories/TEXONET-20030908.txt | Broken LinkURL Repurposed |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/13530 | Third Party AdvisoryVDB Entry |
| https://www.debian.org/security/2003/dsa-396 | Broken Link |
Track CVE-2003-0899 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2003-0899), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.