HAVP: Denial of Service A Denial of Service vulnerability has been reported in HAVP. havp 2008-09-21 2008-09-21 234715 remote 0.89 0.89

HAVP is a HTTP AntiVirus Proxy.

Peter Warasin reported an infinite loop in sockethandler.cpp when connecting to a non-responsive HTTP server.

A remote attacker could send requests to unavailable servers, resulting in a Denial of Service.

There is no known workaround at this time.

All HAVP users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-proxy/havp-0.89"
CVE-2008-3688 p-y p-y p-y