CVE-2007-4337
streamripper - potential code execution
EPSS 3.5%
Description
Multiple buffer overflows in the httplib_parse_sc_header function in lib/http.c in Streamripper before 1.62.2 allow remote attackers to execute arbitrary code via long (1) Location and (2) Server HTTP headers, a different vulnerability than CVE-2006-3124.
How to fix CVE-2007-4337
To remediate CVE-2007-4337, upgrade the affected package to a fixed version below.
- Debian/streamripper—upgrade to 1.62.2-1 or later
- Debian/streamripper—upgrade to 1.61.27-1+etch1 or later
Is CVE-2007-4337 being exploited?
Low — EPSS is 3.5%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 1.62.2-1
- from 0, < 1.61.27-1+etch1