5

CVE-2009-3305

Polipo 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a Cache-Control header that lacks a value for the max-age field, which triggers a segmentation fault in the httpParseHeaders function in http_parse.c, and possibly other unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pps.JussieuPolipo Version1.0.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 10.07% 0.95
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=547047
http://groups.google.com/group/linux.debian.bugs.dist/browse_thread/thread/dca6877a8117f0df
http://secunia.com/advisories/37607
Vendor Advisory
http://secunia.com/advisories/38647
http://www.debian.org/security/2010/dsa-2002
http://www.securityfocus.com/bid/37463