Mandriva Linux Security Advisory 2010-181 – The checkHTTPpassword function in http.c in ntop 3.3.10 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an Authorization HTTP header that lacks a : character in the base64-decoded string. The updated packages have been patched to correct this issue.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/93850/MDVSA-2010-181.txt
Source: https://packetstormsecurity.com/files/93850/Mandriva-Linux-Security-Advisory-2010-181.html

