CVE-2013-7401
CVE-2013-7401
The parse_request function in request.c in c-icap 0.2.x allows remote attackers to cause a denial of service (crash) via a URI without a " " or "?" character in an ICAP request, as demonstrated by use of the OPTIONS method.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://advisories.mageia.org/MGASA-2014-0530.htmlhttp://openwall.com/lists/oss-security/2014/09/15/6http://osvdb.org/ref/89/c-icap.txthttp://security.gentoo.org/glsa/glsa-201409-07.xmlhttp://sourceforge.net/p/c-icap/code/1018/http://www.mandriva.com/security/advisories?name=MDVSA-2015:001http://www.osvdb.org/89304