CVE-2009-4413
Publication date 24 December 2009
Last updated 24 July 2024
Ubuntu priority
The httpClientDiscardBody function in client.c in Polipo 0.9.8, 0.9.12, 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a large Content-Length value, which triggers an integer overflow, a signed-to-unsigned conversion error with a negative value, and a segmentation fault.
Status
Package | Ubuntu Release | Status |
---|---|---|
polipo | 9.10 karmic |
Not affected
|
9.04 jaunty |
Fixed 1.0.4-1+lenny1build0.9.04.1
|
|
8.10 intrepid |
Fixed 1.0.4-1+lenny1build0.8.10.1
|
|
8.04 LTS hardy |
Fixed 1.0.4-1+lenny1build0.8.04.1
|
|
6.06 LTS dapper | Ignored end of life |