7.8
CVSSv2

CVE-2013-1839

Published: 30/09/2013 Updated: 10/10/2013
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The strHdrAcptLangGetItem function in errorpage.cc in Squid 3.2.x prior to 3.2.9 and 3.3.x prior to 3.3.3 allows remote malicious users to cause a denial of service (infinite loop and CPU consumption) via a "," character in an Accept-Language header.

Vulnerable Product Search on Vulmon Subscribe to Product

squid-cache squid 3.3.2

squid-cache squid 3.2.0.1

squid-cache squid 3.2.0.10

squid-cache squid 3.2.0.11

squid-cache squid 3.2.0.12

squid-cache squid 3.2.0.7

squid-cache squid 3.2.0.8

squid-cache squid 3.2.0.9

squid-cache squid 3.2.1

squid-cache squid 3.2.0.17

squid-cache squid 3.2.0.18

squid-cache squid 3.2.0.19

squid-cache squid 3.2.0.2

squid-cache squid 3.2.6

squid-cache squid 3.2.7

squid-cache squid 3.2.8

squid-cache squid 3.3.0.2

squid-cache squid 3.3.1

squid-cache squid 3.2.0.14

squid-cache squid 3.2.0.16

squid-cache squid 3.2.0.3

squid-cache squid 3.2.0.5

squid-cache squid 3.2.3

squid-cache squid 3.2.5

squid-cache squid 3.3.0

squid-cache squid 3.3.0.3

squid-cache squid 3.2.0.13

squid-cache squid 3.2.0.15

squid-cache squid 3.2.0.4

squid-cache squid 3.2.0.6

squid-cache squid 3.2.2

squid-cache squid 3.2.4