PT-2009-6671 · Debian · Yaws+5

Praveen Darshanam

·

Published

1970-01-01

·

Updated

2017-09-29

·

CVE-2009-0751

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions yaws versions prior to 1.80 yaws-chat (affected versions not specified) yaws-wiki (affected versions not specified) yaws-yapp (affected versions not specified) yaws-mail (affected versions not specified)
Description The issue is related to multiple vulnerabilities in the yaws package of the Debian GNU/Linux operating system, which can lead to a disruption of protected information. These vulnerabilities can be exploited remotely. According to the information, a request with a large number of headers can cause a denial of service, resulting in memory consumption and a crash.
Recommendations For yaws versions prior to 1.80, update to version 1.80 or later to resolve the issue. For yaws-chat, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For yaws-wiki, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For yaws-yapp, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For yaws-mail, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01931
BDU:2015-01932
BDU:2015-01933
BDU:2015-01934
BDU:2015-01935
CVE-2009-0751
DSA-1740-1

Affected Products

Debian
Yaws
Yaws-Chat
Yaws-Mail
Yaws-Wiki
Yaws-Yapp