Vulnerability Description
Buffer overflow in lib/load_http.c in ippool in Darren Reed IPFilter (aka IP Filter) 4.1.31 allows local users to gain privileges via vectors involving a long hostname in a URL.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Darren Reed | Ipfilter | 4.1.31 |
Related Weaknesses (CWE)
References
- http://cvsweb.netbsd.org/bsdweb.cgi/src/dist/ipf/lib/load_http.c
- http://cvsweb.netbsd.org/bsdweb.cgi/src/dist/ipf/lib/load_http.c.diff?r1=1.1&r2=
- http://securityreason.com/achievement_securityalert/62Exploit
- http://www.securityfocus.com/bid/35076
- http://www.securitytracker.com/id?1022272
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50716
- http://cvsweb.netbsd.org/bsdweb.cgi/src/dist/ipf/lib/load_http.c
- http://cvsweb.netbsd.org/bsdweb.cgi/src/dist/ipf/lib/load_http.c.diff?r1=1.1&r2=
- http://securityreason.com/achievement_securityalert/62Exploit
- http://www.securityfocus.com/bid/35076
- http://www.securitytracker.com/id?1022272
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50716
FAQ
What is CVE-2009-1476?
CVE-2009-1476 is a vulnerability with a CVSS score of 7.2 (HIGH). Buffer overflow in lib/load_http.c in ippool in Darren Reed IPFilter (aka IP Filter) 4.1.31 allows local users to gain privileges via vectors involving a long hostname in a URL.
How severe is CVE-2009-1476?
CVE-2009-1476 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-1476?
Check the references section above for vendor advisories and patch information. Affected products include: Darren Reed Ipfilter.