vendor:
Polipo
by:
Jeremy Brown
7.5
CVSS
HIGH
Remote Memory Corruption
119
CWE
Product Name: Polipo
Affected Version From: 2000.9.8
Affected Version To: 1.0.4
Patch Exists: NO
Related CWE:
CPE: a:polipo:polipo:1.0.4
Platforms Tested:
2009
Polipo Remote Memory Corruption
The exploit is a proof of concept for a remote memory corruption vulnerability in Polipo version 1.0.4. The vulnerability is caused by a flaw in the client.c file of Polipo, where a memmove function call does not properly handle the reqlen and reqbegin variables. This can lead to a segmentation fault and potential remote code execution.
Mitigation:
Upgrade to a non-vulnerable version of Polipo. No official patch is available.