7.8
CVSSv2

CVE-2006-0046

Published: 13/02/2006 Updated: 07/11/2023
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

squid_redirect script in adzapper prior to 2006-01-29 allows remote malicious users to cause a denial of service (CPU consumption) via a URL with a large number of trailing / (forward slashes), which might produce inefficient regular expressions.

Vulnerable Product Search on Vulmon Subscribe to Product

cameron simpson adzapper 2006-01-24

cameron simpson adzapper 2006-01-01

cameron simpson adzapper 2006-01-23

cameron simpson adzapper 2006-01-05

cameron simpson adzapper 2006-01-15

cameron simpson adzapper 2006-01-29

cameron simpson adzapper 2006-01-25

cameron simpson adzapper 2006-01-07

cameron simpson adzapper 2006-01-28

cameron simpson adzapper 2006-01-14

Vendor Advisories

Thomas Reifferscheid discovered that adzapper, a proxy advertisement zapper add-on, when installed as plugin in squid, the Internet object cache, can consume a lot of CPU resources and hence cause a denial of service on the proxy host The old stable distribution (woody) does not contain an adzapper package For the stable distribution (sarge) this ...