FreeBSD : Pavuk HTTP Location header overflow (76904dce-ccf3-11d8-babb-000854d03344)
High Nessus Plugin ID 36618
SynopsisThe remote FreeBSD host is missing a security-related update.
DescriptionWhen pavuk sends a request to a web server and the server sends back the HTTP status code 305 (Use Proxy), pavuk copies data from the HTTP Location header in an unsafe manner. This leads to a stack-based buffer overflow with control over EIP.
SolutionUpdate the affected package.