CVE-2009-4413

Publication date 24 December 2009

Last updated 24 July 2024


Ubuntu priority

The httpClientDiscardBody function in client.c in Polipo 0.9.8, 0.9.12, 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a large Content-Length value, which triggers an integer overflow, a signed-to-unsigned conversion error with a negative value, and a segmentation fault.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
polipo 9.10 karmic
Not affected
9.04 jaunty
Fixed 1.0.4-1+lenny1build0.9.04.1
8.10 intrepid
Fixed 1.0.4-1+lenny1build0.8.10.1
8.04 LTS hardy
Fixed 1.0.4-1+lenny1build0.8.04.1
6.06 LTS dapper Ignored end of life