CVE-2009-3305

EPSS 11.7%

polipo - denial of service

Published: 12/24/2009Modified: 3/9/2026

Description

Polipo 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a Cache-Control header that lacks a value for the max-age field, which triggers a segmentation fault in the httpParseHeaders function in http_parse.c, and possibly other unspecified vectors.

Affected packages (2)

References (6)