5
CVSSv2

CVE-2009-2855

Published: 18/08/2009 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote malicious users to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.

Vulnerable Product Search on Vulmon Subscribe to Product

squid-cache squid 2.7

Vendor Advisories

Synopsis Low: squid security and bug fix update Type/Severity Security Advisory: Low Topic An updated squid package that fixes two security issues and several bugs isnow available for Red Hat Enterprise Linux 5The Red Hat Security Response Team has rated this update as having lowsecurity impact Common Vul ...
Debian Bug report logs - #534982 squid - DoS in external auth header parser Package: squid; Maintainer for squid is Luigi Gangitano <luigi@debianorg>; Source for squid is src:squid (PTS, buildd, popcon) Reported by: Bastian Blank <waldi@debianorg> Date: Sun, 28 Jun 2009 18:21:02 UTC Severity: critical Tags: fixed- ...
It was discovered that Squid incorrectly handled certain auth headers A remote attacker could exploit this with a specially-crafted auth header and cause Squid to go into an infinite loop, resulting in a denial of service This issue only affected Ubuntu 810, 904 and 910 (CVE-2009-2855) ...
Two denial of service vulnerabilities have been discovered in squid and squid3, a web proxy The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-2855 Bastian Blank discovered that it is possible to cause a denial of service via a crafted auth header with certain comma delimiters CVE-2010-0308 Tomas Hoger d ...