All errata/sisyphus/ALT-PU-2014-2160-1
ALT-PU-2014-2160-1

Package update polipo in branch sisyphus

Version1.1.1-alt1
Published2014-09-19
Max severityHIGH
Severity:

Closed issues (4)

BDU:2015-03389
MEDIUM5.0

Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить доступность защищаемой информации

Published: 2015-04-28Modified: 2024-07-05
CVSS 2.0MEDIUM 5.0
CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:N/A:P
CVE-2009-3305
MEDIUM5.0

Polipo 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a Cache-Control header that lacks a value for the max-age field, which triggers a segmentation fault in the httpParseHeaders function in http_parse.c, and possibly other unspecified vectors.

Published: 2009-12-24Modified: 2026-04-23
CVSS 2.0MEDIUM 5.0
CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:N/A:P
CVE-2009-4413
MEDIUM5.0

The httpClientDiscardBody function in client.c in Polipo 0.9.8, 0.9.12, 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a large Content-Length value, which triggers an integer overflow, a signed-to-unsigned conversion error with a negative value, and a segmentation fault.

Published: 2009-12-24Modified: 2026-04-23
CVSS 2.0MEDIUM 5.0
CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:N/A:P