CVE-2009-3305
Dashboard / Vulnerabilities / CVE-2009-3305
CVE-2009-3305
Summary:
Details: Polipo 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a Cache-Control header that lacks a value for the max-age field, which triggers a segmentation fault in the httpParseHeaders function in http_parse.c, and possibly other unspecified vectors.
References: http://secunia.com/advisories/37607, http://secunia.com/advisories/38647, http://www.debian.org/security/2010/dsa-2002, http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=547047, http://groups.google.com/group/linux.debian.bugs.dist/browse_thread/thread/dca6877a8117f0df, http://www.securityfocus.com/bid/37463
Affected packages
Package
Name: polipo
Purl: pkg:deb/debian/polipo?arch=source
Affected ranges
Type: ECOSYSTEM
Events:
