Candidate: CVE-2009-2732 PublicDate: 2009-08-21 11:02:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2732 Description: The checkHTTPpassword function in http.c in ntop 3.3.10 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an Authorization HTTP header that lacks a : (colon) character in the base64-decoded string. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_ntop: upstream_ntop: needs-triage dapper_ntop: ignored (reached end-of-life) hardy_ntop: ignored (reached end-of-life) intrepid_ntop: needed (reached end-of-life) jaunty_ntop: ignored (reached end-of-life) karmic_ntop: ignored (reached end-of-life) lucid_ntop: not-affected (3:3.3-12) maverick_ntop: not-affected (3:3.3-12) natty_ntop: not-affected (3:3.3-12) oneiric_ntop: not-affected (3:3.3-12) devel_ntop: not-affected (3:3.3-12)