Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-3688

Опубликовано: 14 авг. 2008
Источник: nvd
CVSS3: 7.5
CVSS2: 4.3
EPSS Низкий

Описание

sockethandler.cpp in HTTP Antivirus Proxy (HAVP) 0.88 allows remote attackers to cause a denial of service (hang) by connecting to a non-responsive server, which triggers an infinite loop due to an uninitialized variable.

Комментарий

https://sourceforge.net/mailarchive/message.php?msg_name=487CDF51.5060201%40endian.com

"Afterwards it retries in a loop. This retry loop is infinite, due to a not initialised variable. This happens also only if you use a parent proxy and if the parent proxy is a numerical ip address, which don't need to be resolved."

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:havp:http_antivirus_proxy:0.88:*:*:*:*:*:*:*

EPSS

Процентиль: 84%
0.02104
Низкий

7.5 High

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-908

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 17 лет назад

sockethandler.cpp in HTTP Antivirus Proxy (HAVP) 0.88 allows remote attackers to cause a denial of service (hang) by connecting to a non-responsive server, which triggers an infinite loop due to an uninitialized variable.

CVSS3: 7.5
debian
больше 17 лет назад

sockethandler.cpp in HTTP Antivirus Proxy (HAVP) 0.88 allows remote at ...

CVSS3: 7.5
github
почти 4 года назад

sockethandler.cpp in HTTP Antivirus Proxy (HAVP) 0.88 allows remote attackers to cause a denial of service (hang) by connecting to a non-responsive server, which triggers an infinite loop due to an uninitialized variable.

EPSS

Процентиль: 84%
0.02104
Низкий

7.5 High

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-908