PT-2021-6719 · Polipo · Polipo
Alexandr Savca
+1
·
Published
2021-07-14
·
Updated
2024-08-04
·
CVE-2020-36420
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Polipo versions 1.1.1 and earlier
Description
The issue is related to the insufficient use of the
assert() function in the Polipo proxy server, allowing a remote attacker to cause a denial of service. This can be achieved by parsing a malformed Range header, leading to a reachable assertion. The vulnerability only affects products that are no longer supported by the maintainer.Recommendations
For Polipo versions 1.1.1 and earlier, consider disabling the parsing of Range headers as a temporary workaround until a patch is available. Restrict access to the proxy server to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Assertion Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Polipo