PT-2021-6719 · Polipo · Polipo

Alexandr Savca

+1

·

Published

2021-07-14

·

Updated

2024-08-04

·

CVE-2020-36420

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Polipo versions 1.1.1 and earlier
Description The issue is related to the insufficient use of the assert() function in the Polipo proxy server, allowing a remote attacker to cause a denial of service. This can be achieved by parsing a malformed Range header, leading to a reachable assertion. The vulnerability only affects products that are no longer supported by the maintainer.
Recommendations For Polipo versions 1.1.1 and earlier, consider disabling the parsing of Range headers as a temporary workaround until a patch is available. Restrict access to the proxy server to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Assertion Failure

Weakness Enumeration

Related Identifiers

BDU:2022-02089
CVE-2020-36420

Affected Products

Polipo