Vulnerability record · CVE-2009-3711 · published 16 October 2009
CVE-2009-3711: httpdx HTTP GET stack buffer overflow in h_handlepeer
Jasper · Httpdx
httpdx 1.4 (and possibly 1.4.3) contains a stack-based buffer overflow in the h_handlepeer function in http.cpp, triggered by a long HTTP GET request. A remote, unauthenticated attacker can crash the server and possibly execute arbitrary code, making this a full-impact flaw for any exposed instance.
Description
Stack-based buffer overflow in the h_handlepeer function in http.cpp in httpdx 1.4, and possibly 1.4.3, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10 with network, unauthenticated, full-impact characteristics and public exploit references, though no confirmed in-the-wild exploitation per KEV.
What it is
httpdx 1.4 (and possibly 1.4.3) contains a stack-based buffer overflow in the h_handlepeer function in http.cpp, triggered by a long HTTP GET request. A remote, unauthenticated attacker can crash the server and possibly execute arbitrary code, making this a full-impact flaw for any exposed instance.
Impact
An attacker gains the ability to crash the httpdx service and potentially execute arbitrary code with the privileges of the server process, which per the CVSS vector implies full confidentiality, integrity and availability loss.
Attack surface
Reachable over the network via a crafted HTTP GET request to the httpdx listener; no authentication or user interaction is required (AV:N/AC:L/Au:N).
Exploitation
Public exploit references are tagged in the record, and EPSS is high (0.639, 99th percentile), but the CVE is not listed in CISA KEV, so active exploitation in the wild is not confirmed by the supplied data.
What to do
- Upgrade httpdx to a version later than 1.4.3 if one is available; the record does not name a fixed version, so verify with the vendor.
- If no patch exists, remove httpdx from internet-facing exposure or place it behind a reverse proxy that enforces strict request-line length limits.
- Restrict network access to the httpdx service to trusted hosts only.
- Run the service under a low-privilege account and enable OS-level exploit mitigations (ASLR, DEP) to limit code execution impact.
- Monitor vendor advisories for httpdx for a fixed release.
Detection
- Inspect HTTP server logs for abnormally long GET request lines or request URIs targeting httpdx.
- Alert on httpdx process crashes or restarts, which may indicate a failed overflow attempt.
- Use network IDS signatures for oversized HTTP GET requests to the httpdx port.
- Watch for unexpected child processes or outbound connections spawned by the httpdx process.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-3711 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-3711), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.