5
CVSSv2

CVE-2009-0751

Published: 02/03/2009 Updated: 29/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Yaws prior to 1.80 allows remote malicious users to cause a denial of service (memory consumption and crash) via a request with a large number of headers.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

yaws yaws 1.55

yaws yaws 1.56

yaws yaws 1.65

yaws yaws 1.66

yaws yaws 1.74

yaws yaws 1.75

yaws yaws 1.57

yaws yaws 1.58

yaws yaws 1.67

yaws yaws 1.68

yaws yaws 1.76

yaws yaws 1.77

yaws yaws 1.53

yaws yaws 1.54

yaws yaws 1.63

yaws yaws 1.64

yaws yaws 1.72

yaws yaws 1.73

yaws yaws 1.50

yaws yaws 1.51

yaws yaws 1.52

yaws yaws 1.61

yaws yaws 1.62

yaws yaws 1.70

yaws yaws 1.71

yaws yaws 1.78

yaws yaws

Vendor Advisories

It was discovered that yaws, a high performance HTTP 11 webserver, is prone to a denial of service attack via a request with a large HTTP header For the stable distribution (lenny), this problem has been fixed in version 177-3+lenny1 For the oldstable distribution (etch), this problem has been fixed in version 165-4etch1 For the testing distr ...

Exploits

#!usr/bin/perl -w ####################################################################################### # Yaws before 180 allows remote attackers to cause a denial of service (memory # consumption and crash) via a request with a large number of headers # Refer: # yawshyberorg/ # wwwsecurityfocuscom/bid/338 ...
Yaws versions prior to 180 remote denial of service exploit ...