CVE Vulnerabilities

CVE-2009-4413

Published: Dec 24, 2009 | Modified: Feb 26, 2010
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The httpClientDiscardBody function in client.c in Polipo 0.9.8, 0.9.12, 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a large Content-Length value, which triggers an integer overflow, a signed-to-unsigned conversion error with a negative value, and a segmentation fault.

Affected Software

Name Vendor Start Version End Version
Polipo Pps.jussieu 0.9.8 (including) 0.9.8 (including)
Polipo Pps.jussieu 0.9.12 (including) 0.9.12 (including)
Polipo Pps.jussieu 1.0.4 (including) 1.0.4 (including)
Polipo Ubuntu dapper *
Polipo Ubuntu hardy *
Polipo Ubuntu intrepid *
Polipo Ubuntu jaunty *
Polipo Ubuntu upstream *

References