FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Pavuk HTTP Location header overflow

Affected packages
pavuk < 0.9.28_5

Details

VuXML ID 76904dce-ccf3-11d8-babb-000854d03344
Discovery 2004-06-30
Entry 2004-07-03

When pavuk sends a request to a web server and the server sends back the HTTP status code 305 (Use Proxy), pavuk copies data from the HTTP Location header in an unsafe manner. This leads to a stack-based buffer overflow with control over EIP.

References

CVE Name CVE-2004-0456
Message http://lists.netsys.com/pipermail/full-disclosure/2004-July/023322.html
URL http://www.osvdb.org/7319