CVE-2009-2855
18.08.2009, 21:00
The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.Enginsight
| Vendor | Product | Version |
|---|---|---|
| squid-cache | squid | 2.7 |
| squid-cache | squid | 2.7:stable3 |
| squid-cache | squid | 2.7:stable4 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| squid |
| ||||||||||||||||||
| squid3 |
|
Common Weakness Enumeration
References