5
CVE-2009-3305
- EPSS 10.07%
- Veröffentlicht 24.12.2009 16:30:00
- Zuletzt bearbeitet 16.06.2026 23:11:21
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Polipo 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a Cache-Control header that lacks a value for the max-age field, which triggers a segmentation fault in the httpParseHeaders function in http_parse.c, and possibly other unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pps.Jussieu ≫ Polipo Version1.0.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 10.07% | 0.95 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=547047
http://groups.google.com/group/linux.debian.bugs.dist/browse_thread/thread/dca6877a8117f0df
http://secunia.com/advisories/37607
http://secunia.com/advisories/38647
http://www.debian.org/security/2010/dsa-2002
http://www.securityfocus.com/bid/37463