Back to Database
Status published
High
CVE-2009-1476
Buffer overflow in lib/load_http.c in ippool in Darren Reed IPFilter...
Vulnerability Description
Buffer overflow in lib/load_http.c in ippool in Darren Reed IPFilter (aka IP Filter) 4.1.31 allows local users to gain privileges via vectors involving a long hostname in a URL.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-1476
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/35076
- http://cvsweb.netbsd.org/bsdweb.cgi/src/dist/ipf/lib/load_http.c
- http://www.securitytracker.com/id?1022272
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50716
- http://cvsweb.netbsd.org/bsdweb.cgi/src/dist/ipf/lib/load_http.c.diff?r1=1.1&r2=1.2&f=h
- http://securityreason.com/achievement_securityalert/62
More from darren reed
View All →CVE-2002-1978
IPFilter 3.1.1 through 3.4.28 allows remote attackers to bypass firewall...
High
7.5
CVE-2001-0402
IPFilter 3.4.16 and earlier does not include sufficient session information...
High
7.5
CVE-2000-0553
Race condition in IPFilter firewall 3.4.3 and earlier, when configured...
Low
2.6
CVE-1999-1244
IPFilter 3.2.3 through 3.2.10 allows local users to modify arbitrary...
High
7.2
Affected Vendor
darren reed
View all reports →Affected Software
ipfilter
Vulnerable Versions:
4.1.31
Timeline
Official Publish:
May 26th, 2009
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.