CVE-2009-3305

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
24/12/2009
Last modified:
09/04/2025

Description

Polipo 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a Cache-Control header that lacks a value for the max-age field, which triggers a segmentation fault in the httpParseHeaders function in http_parse.c, and possibly other unspecified vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pps.jussieu:polipo:1.0.4:*:*:*:*:*:*:*