CVE-2012-5875
Firefly Media Server 1.0.0.1359 - Denial of Service via Crafted HTTP Headers
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-5875. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary The exploit demonstrates multiple NULL pointer dereference vulnerabilities in FireFly MediaServer 1.0.0.1359, allowing remote DoS via malformed HTTP headers (CONNECTION, ACCEPT-LANGUAGE, USER-AGENT, HOST). Proof-of-concept HTTP requests are provided to trigger crashes.
Description
Firefly Media Server 1.0.0.1359 allows remote attackers to cause a denial of service (NULL pointer dereference) via a (1) crafted Connection HTTP header; a return carriage control character in the (2) Accept Language header, (3) User-agent header, (4) Host header, or (5) protocol version; or a (6) crafted HTTP protocol version.
Exploits (1)
The exploit demonstrates multiple NULL pointer dereference vulnerabilities in FireFly MediaServer 1.0.0.1359, allowing remote DoS via malformed HTTP headers (CONNECTION, ACCEPT-LANGUAGE, USER-AGENT, HOST). Proof-of-concept HTTP requests are provided to trigger crashes.