Record summary

CVE-2009-2732 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.

Description

The checkHTTPpassword function in http.c in ntop 3.3.10 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an Authorization HTTP header that lacks a : (colon) character in the base64-decoded string.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBntop 3.3.10 - HTTP Basic Authentication Null Pointer Dereference Denial of ServiceExploitDB exploitby Brad AntoniewiczNot analyzed1 file
ExploitDB

PoC details

References

6