Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-2855

Опубликовано: 28 июн. 2009
Источник: redhat
CVSS2: 2.9
EPSS Средний

Описание

The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.

Отчет

This issue did not affect the versions of the squid packages, as shipped with Red Hat Enterprise Linux 3 and 4.

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=518182squid: DoS (100% CPU use) while processing certain external ACL helper HTTP headers

EPSS

Процентиль: 98%
0.60658
Средний

2.9 Low

CVSS2

Связанные уязвимости

ubuntu
почти 16 лет назад

The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.

nvd
почти 16 лет назад

The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.

debian
почти 16 лет назад

The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allo ...

github
около 3 лет назад

The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.

oracle-oval
около 15 лет назад

ELSA-2010-0221: squid security and bug fix update (LOW)

EPSS

Процентиль: 98%
0.60658
Средний

2.9 Low

CVSS2