CVE-2009-2732
MEDIUM 5.0EPSS 7.3%
The checkHTTPpassword function in http.c in ntop 3.3.10 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an Authorization HTTP header that lacks a : (colon) character in the base64-decoded string.
- CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P - EPSS
- 7.27% chance of exploitation in the next 30 days, 94th percentile
- Published
- 2009-08-20
- Updated
- 2024-08-07