{"id":"UBUNTU-CVE-2012-5875","details":"Firefly Media Server 1.0.0.1359 allows remote attackers to cause a denial of service (NULL pointer dereference) via a (1) crafted Connection HTTP header; a return carriage control character in the (2) Accept Language header, (3) User-agent header, (4) Host header, or (5) protocol version; or a (6) crafted HTTP protocol version.","modified":"2025-07-08T14:32:16.045202Z","published":"2013-01-18T11:48:00Z","withdrawn":"2025-07-08T10:45:17Z","upstream":["CVE-2012-5875"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2012-5875"},{"type":"REPORT","url":"https://www.htbridge.com/advisory/HTB23129"},{"type":"REPORT","url":"http://www.securitytracker.com/id?1027917"},{"type":"REPORT","url":"http://www.exploit-db.com/exploits/23574"},{"type":"REPORT","url":"http://archives.neohapsis.com/archives/bugtraq/2012-12/0115.html"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2012-5875"}],"affected":[{"package":{"name":"forked-daapd","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/forked-daapd@23.3-1?arch=source&distro=esm-apps/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["23.2-1build1","23.3-1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2012/UBUNTU-CVE-2012-5875.json"}},{"package":{"name":"forked-daapd","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/forked-daapd@25.0-2build4?arch=source&distro=esm-apps/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["25.0-1","25.0-2","25.0-2build1","25.0-2build2","25.0-2build4"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2012/UBUNTU-CVE-2012-5875.json"}}],"schema_version":"1.7.3","severity":[{"score":"medium"}]}