CVE-2009-3305

Polipo 1.0.4 - Denial of Service via Cache-Control Header Parsing

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-3305.

AI-analyzed exploit summary This Perl script exploits a memory corruption vulnerability in Polipo 1.0.4 by sending a crafted HTTP request with an invalid Content-Length header, triggering a segmentation fault in the memmove function. The PoC demonstrates the vulnerability but does not achieve remote code execution.

Description

Polipo 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a Cache-Control header that lacks a value for the max-age field, which triggers a segmentation fault in the httpParseHeaders function in http_parse.c, and possibly other unspecified vectors.

Exploits (1)

exploitdb WORKING POC
perldoslinux
https://www.exploit-db.com/exploits/10338

This Perl script exploits a memory corruption vulnerability in Polipo 1.0.4 by sending a crafted HTTP request with an invalid Content-Length header, triggering a segmentation fault in the memmove function. The PoC demonstrates the vulnerability but does not achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Polipo 1.0.4
No auth needed
Prerequisites: Network access to the target Polipo server
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/37463
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/38647
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/37607
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2010/dsa-2002
Issue Tracking x_refsource_confirm
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=547047

Scores

EPSS 0.1172
EPSS Percentile 93.9%

Details

CWE
CWE-20
Status published
Products (1)
pps.jussieu/polipo 1.0.4
Published Dec 24, 2009
Tracked Since Feb 18, 2026