PT-2009-1027 · Polipo+1 · Polipo+1
Stefan Fritsch
·
Publicado
2009-12-24
·
Atualizado
2014-09-19
·
CVE-2009-3305
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Polipo version 1.0.4
Description
The issue allows remote attackers to cause a denial of service, potentially leading to a crash, via a request with a Cache-Control header that lacks a value for the
max-age field. This triggers a segmentation fault in the httpParseHeaders function in http parse.c. There are possibly other unspecified vectors for this issue. The exploitation of these vulnerabilities can lead to disruption of protected information and can be carried out remotely.Recommendations
For Polipo version 1.0.4, consider disabling the
httpParseHeaders function in http parse.c as a temporary workaround until a patch is available. Restrict access to the Cache-Control header to minimize the risk of exploitation. Avoid using the max-age field without a value in the Cache-Control header until the issue is resolved.Exploit
Correção
DoS
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Polipo