漏洞信息详情
Pps.Jussieu Polipo服务器超长HTTP头远程拒绝服务漏洞
漏洞简介
Polipo是一个小型的代理服务器软件。
Polipo的client.c文件中的httpClientDiscardBody()函数中存在符号错误,远程攻击者可以通过提交带有超长Content-Length头的HTTP请求导致服务崩溃;此外http_parse.c的httpParseHeaders()函数没有正确地解析某些Cache-Control头,发送畸形的HTTP请求也可能导致拒绝服务。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Debian Linux 5.0 hppa
Debian polipo_1.0.4-1+lenny1_hppa.deb
http://security.debian.org/pool/updates/main/p/polipo/polipo_1.0.4-1+l enny1_hppa.deb
Debian Linux 5.0 ia-64
Debian polipo_1.0.4-1+lenny1_ia64.deb
http://security.debian.org/pool/updates/main/p/polipo/polipo_1.0.4-1+l enny1_ia64.deb
Debian Linux 5.0 arm
Debian polipo_1.0.4-1+lenny1_arm.deb
http://security.debian.org/pool/updates/main/p/polipo/polipo_1.0.4-1+l enny1_arm.deb
Debian Linux 5.0 armel
Debian polipo_1.0.4-1+lenny1_armel.deb
http://security.debian.org/pool/updates/main/p/polipo/polipo_1.0.4-1+l enny1_armel.deb
Debian Linux 5.0 alpha
Debian polipo_1.0.4-1+lenny1_alpha.deb
http://security.debian.org/pool/updates/main/p/polipo/polipo_1.0.4-1+l enny1_alpha.deb
Debian Linux 5.0 amd64
Debian polipo_1.0.4-1+lenny1_amd64.deb
http://security.debian.org/pool/updates/main/p/polipo/polipo_1.0.4-1+l enny1_amd64.deb
Debian Linux 5.0 ia-32
Debian polipo_1.0.4-1+lenny1_i386.deb
http://security.debian.org/pool/updates/main/p/polipo/polipo_1.0.4-1+l enny1_i386.deb
Debian Linux 5.0 mips
Debian polipo_1.0.4-1+lenny1_mips.deb
http://security.debian.org/pool/updates/main/p/polipo/polipo_1.0.4-1+l enny1_mips.deb
Debian Linux 5.0 s/390
Debian polipo_1.0.4-1+lenny1_s390.deb
http://security.debian.org/pool/updates/main/p/polipo/polipo_1.0.4-1+l enny1_s390.deb
Debian Linux 5.0 mipsel
Debian polipo_1.0.4-1+lenny1_mipsel.deb
http://security.debian.org/pool/updates/main/p/polipo/polipo_1.0.4-1+l enny1_mipsel.deb
Debian Linux 5.0 powerpc
Debian polipo_1.0.4-1+lenny1_powerpc.deb
http://security.debian.org/pool/updates/main/p/polipo/polipo_1.0.4-1+l enny1_powerpc.deb
Debian Linux 5.0 sparc
Debian polipo_1.0.4-1+lenny1_sparc.deb
http://security.debian.org/pool/updates/main/p/polipo/polipo_1.0.4-1+l enny1_sparc.deb
参考网址
来源: BID
名称: 37463
链接:http://www.securityfocus.com/bid/37463
来源: SECUNIA
名称: 37607
链接:http://secunia.com/advisories/37607
来源: groups.google.com
链接:http://groups.google.com/group/linux.debian.bugs.dist/browse_thread/thread/dca6877a8117f0df
来源: bugs.debian.org
链接:http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=547047
受影响实体
- Pps.Jussieu Polipo:1.0.4<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...