CVE-2014-5015

bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrictions, which allows remote attackers to bypass the HTTP authentication scheme and access restrictions via a long path.

Published: 2014-07-24 Last update: 2026-05-06 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2014-5015 is rated Moderate Risk (43.4/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.57%). Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2014-5015

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-03-17 0.52% 0.57% +0.06%
2 2024-06-05 0.72% 0.52% -0.20%
3 2023-03-07 0.72%

Full EPSS history (4 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2014-5015

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
5.0 2.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:N)
No availability impact.
10.0 2.9 [email protected]

Weakness enumeration for CVE-2014-5015

OS Trackers for CVE-2014-5015

vendor priority summary link
ubuntu medium CVE-2014-5015 medium priority: Ubuntu including 1 source packages (bozohttpd), 10 status rows across 10 suites (lucid, precise, trusty, upstream, utopic, vivid, wily, xenial, yakkety, zesty): DNE 5, ignored 3, released 2. https://ubuntu.com/security/CVE-2014-5015

Affected software / configurations for CVE-2014-5015

Vendor Product Version Raw CPE
eterna bozohttpd <= 20140201 cpe:2.3:a:eterna:bozohttpd:*:*:*:*:*:*:*:*
eterna bozohttpd 19990519 cpe:2.3:a:eterna:bozohttpd:19990519:*:*:*:*:*:*:*
eterna bozohttpd 20000421 cpe:2.3:a:eterna:bozohttpd:20000421:*:*:*:*:*:*:*
eterna bozohttpd 20000426 cpe:2.3:a:eterna:bozohttpd:20000426:*:*:*:*:*:*:*
eterna bozohttpd 20000427 cpe:2.3:a:eterna:bozohttpd:20000427:*:*:*:*:*:*:*
eterna bozohttpd 20000815 cpe:2.3:a:eterna:bozohttpd:20000815:*:*:*:*:*:*:*
eterna bozohttpd 20000825 cpe:2.3:a:eterna:bozohttpd:20000825:*:*:*:*:*:*:*
eterna bozohttpd 20010610 cpe:2.3:a:eterna:bozohttpd:20010610:*:*:*:*:*:*:*
eterna bozohttpd 20010812 cpe:2.3:a:eterna:bozohttpd:20010812:*:*:*:*:*:*:*
eterna bozohttpd 20010922 cpe:2.3:a:eterna:bozohttpd:20010922:*:*:*:*:*:*:*
eterna bozohttpd 20020710 cpe:2.3:a:eterna:bozohttpd:20020710:*:*:*:*:*:*:*
eterna bozohttpd 20020730 cpe:2.3:a:eterna:bozohttpd:20020730:*:*:*:*:*:*:*
eterna bozohttpd 20020803 cpe:2.3:a:eterna:bozohttpd:20020803:*:*:*:*:*:*:*
eterna bozohttpd 20020804 cpe:2.3:a:eterna:bozohttpd:20020804:*:*:*:*:*:*:*
eterna bozohttpd 20020823 cpe:2.3:a:eterna:bozohttpd:20020823:*:*:*:*:*:*:*
eterna bozohttpd 20020913 cpe:2.3:a:eterna:bozohttpd:20020913:*:*:*:*:*:*:*
eterna bozohttpd 20021106 cpe:2.3:a:eterna:bozohttpd:20021106:*:*:*:*:*:*:*
eterna bozohttpd 20030313 cpe:2.3:a:eterna:bozohttpd:20030313:*:*:*:*:*:*:*
eterna bozohttpd 20030409 cpe:2.3:a:eterna:bozohttpd:20030409:*:*:*:*:*:*:*
eterna bozohttpd 20030626 cpe:2.3:a:eterna:bozohttpd:20030626:*:*:*:*:*:*:*
eterna bozohttpd 20031005 cpe:2.3:a:eterna:bozohttpd:20031005:*:*:*:*:*:*:*
eterna bozohttpd 20040218 cpe:2.3:a:eterna:bozohttpd:20040218:*:*:*:*:*:*:*
eterna bozohttpd 20040808 cpe:2.3:a:eterna:bozohttpd:20040808:*:*:*:*:*:*:*
eterna bozohttpd 20050410 cpe:2.3:a:eterna:bozohttpd:20050410:*:*:*:*:*:*:*
eterna bozohttpd 20060517 cpe:2.3:a:eterna:bozohttpd:20060517:*:*:*:*:*:*:*
eterna bozohttpd 20060710 cpe:2.3:a:eterna:bozohttpd:20060710:*:*:*:*:*:*:*
eterna bozohttpd 20080303 cpe:2.3:a:eterna:bozohttpd:20080303:*:*:*:*:*:*:*
eterna bozohttpd 20090417 cpe:2.3:a:eterna:bozohttpd:20090417:*:*:*:*:*:*:*
eterna bozohttpd 20090522 cpe:2.3:a:eterna:bozohttpd:20090522:*:*:*:*:*:*:*
eterna bozohttpd 20100509 cpe:2.3:a:eterna:bozohttpd:20100509:*:*:*:*:*:*:*
eterna bozohttpd 20100512 cpe:2.3:a:eterna:bozohttpd:20100512:*:*:*:*:*:*:*
eterna bozohttpd 20100617 cpe:2.3:a:eterna:bozohttpd:20100617:*:*:*:*:*:*:*
eterna bozohttpd 20100621 cpe:2.3:a:eterna:bozohttpd:20100621:*:*:*:*:*:*:*
eterna bozohttpd 20100920 cpe:2.3:a:eterna:bozohttpd:20100920:*:*:*:*:*:*:*
eterna bozohttpd 20111118 cpe:2.3:a:eterna:bozohttpd:20111118:*:*:*:*:*:*:*
eterna bozohttpd 20140102 cpe:2.3:a:eterna:bozohttpd:20140102:*:*:*:*:*:*:*
netbsd netbsd 5.1 cpe:2.3:o:netbsd:netbsd:5.1:*:*:*:*:*:*:*
netbsd netbsd 5.2 cpe:2.3:o:netbsd:netbsd:5.2:*:*:*:*:*:*:*
netbsd netbsd 6.0 cpe:2.3:o:netbsd:netbsd:6.0:*:*:*:*:*:*:*
netbsd netbsd 6.1 cpe:2.3:o:netbsd:netbsd:6.1:*:*:*:*:*:*:*

References for CVE-2014-5015

cvelogic Threat Intelligence