GoAhead WebServer before 2.1.5 on Windows 95, 98, and ME allows remote attackers to cause a denial of service (daemon crash) via an HTTP request with a (1) con, (2) nul, (3) clock$, or (4) config$ device name in a path component, different vectors than CVE-2001-0385.
| Software | From | Fixed in |
|---|---|---|
| goahead / goahead_webserver | 2.0 | 2.0.x |
| goahead / goahead_webserver | 2.1.2 | 2.1.2.x |
| goahead / goahead_webserver | 2.1.1 | 2.1.1.x |
| goahead / goahead_webserver | 2.1 | 2.1.x |
| goahead / goahead_webserver | - | 2.1.4.x |
| goahead / goahead_webserver | 2.1.3 | 2.1.3.x |