CVE-2009-4413

The httpClientDiscardBody function in client.c in Polipo 0.9.8, 0.9.12, 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a large Content-Length value, which triggers an integer overflow, a signed-to-unsigned conversion error with a negative value, and a segmentation fault.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
VendorProductVersion
pps.jussieupolipo
0.9.8
pps.jussieupolipo
0.9.12
pps.jussieupolipo
1.0.4
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
polipo
karmic
not-affected
jaunty
Fixed 1.0.4-1+lenny1build0.9.04.1
released
intrepid
Fixed 1.0.4-1+lenny1build0.8.10.1
released
hardy
Fixed 1.0.4-1+lenny1build0.8.04.1
released
dapper
ignored
Common Weakness Enumeration