5

CVE-2009-4413

The httpClientDiscardBody function in client.c in Polipo 0.9.8, 0.9.12, 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a large Content-Length value, which triggers an integer overflow, a signed-to-unsigned conversion error with a negative value, and a segmentation fault.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pps.JussieuPolipo Version0.9.8
Pps.JussieuPolipo Version0.9.12
Pps.JussieuPolipo Version1.0.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.66% 0.944
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/37607
Vendor Advisory
http://secunia.com/advisories/38647
http://www.debian.org/security/2010/dsa-2002
http://www.securityfocus.com/bid/37463
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560779
http://www.exploit-db.com/exploits/10338
http://www.openwall.com/lists/oss-security/2009/12/12/4