CVE-2009-3305
Publication date 24 December 2009
Last updated 24 July 2024
Ubuntu priority
Polipo 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a Cache-Control header that lacks a value for the max-age field, which triggers a segmentation fault in the httpParseHeaders function in http_parse.c, and possibly other unspecified vectors.
Status
Package | Ubuntu Release | Status |
---|---|---|
polipo | 9.10 karmic |
Not affected
|
9.04 jaunty |
Fixed 1.0.4-1+lenny1build0.9.04.1
|
|
8.10 intrepid |
Fixed 1.0.4-1+lenny1build0.8.10.1
|
|
8.04 LTS hardy |
Fixed 1.0.4-1+lenny1build0.8.04.1
|
|
6.06 LTS dapper | Ignored end of life |