Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7hrp-6jq3-pm4q

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.

The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.

EPSS

Процентиль: 98%
0.60658
Средний

Дефекты

CWE-20

Связанные уязвимости

ubuntu
почти 16 лет назад

The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.

redhat
почти 16 лет назад

The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.

nvd
почти 16 лет назад

The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.

debian
почти 16 лет назад

The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allo ...

oracle-oval
около 15 лет назад

ELSA-2010-0221: squid security and bug fix update (LOW)

EPSS

Процентиль: 98%
0.60658
Средний

Дефекты

CWE-20