{"id":"DSA-396","summary":"thttpd - missing input sanitizing, wrong calculation","modified":"2026-03-09T02:11:45.582819Z","published":"2003-10-29T00:00:00Z","upstream":["CVE-2002-1562","CVE-2003-0899","DEBIAN-CVE-2002-1562","DEBIAN-CVE-2003-0899"],"affected":[{"package":{"name":"thttpd","ecosystem":"Debian:3.0","purl":"pkg:deb/debian/thttpd?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.21b-11.2"}]}],"database_specific":{"source":"https://storage.googleapis.com/debian-osv/dsa-osv/DSA-396.json"}}],"schema_version":"1.7.3"}