LWN.net Logo

polipo: denial of service

Package(s):polipo CVE #(s):CVE-2011-3596
Created:February 2, 2012 Updated:February 8, 2012
Description:

From the Red Hat bugzilla entry:

A denial of service flaw was found in the way Polipo, a lightweight caching web proxy, processed certain HTTP POST / PUT requests. If polipo was configured to allow remote client connections and particular host was allowed to connect to polipo server instance, a remote attacker could use this flaw to cause denial of service (polipo daemon abort due to assertion failure) via specially-crafted HTTP POST / PUT request.

Alerts:
Fedora FEDORA-2012-0849 2012-02-01
Fedora FEDORA-2012-0840 2012-02-01

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds