The HTTP client and server in giFT-FastTrack 0.8.6 and earlier allows remote attackers to cause a denial of service (crash), possibly via an empty search query, which triggers a NULL dereference.
| Software | From | Fixed in |
|---|---|---|
| gift-fasttrack / gift-fasttrack | 0.8.1 | 0.8.1.x |
| gift-fasttrack / gift-fasttrack | 0.8.4 | 0.8.4.x |
| gift-fasttrack / gift-fasttrack | 0.8.5 | 0.8.5.x |
| gift-fasttrack / gift-fasttrack | 0.8.3 | 0.8.3.x |
| gift-fasttrack / gift-fasttrack | 0.8.6 | 0.8.6.x |
| gift-fasttrack / gift-fasttrack | 0.8.2 | 0.8.2.x |
| gift-fasttrack / gift-fasttrack | 0.8.0 | 0.8.0.x |
| gentoo / linux | 1.4 | 1.4.x |