Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-2855

Опубликовано: 28 июн. 2009
Источник: redhat
CVSS2: 2.9

Описание

The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.

Отчет

This issue did not affect the versions of the squid packages, as shipped with Red Hat Enterprise Linux 3 and 4.

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=518182squid: DoS (100% CPU use) while processing certain external ACL helper HTTP headers

2.9 Low

CVSS2

Связанные уязвимости

ubuntu
больше 16 лет назад

The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.

nvd
больше 16 лет назад

The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.

debian
больше 16 лет назад

The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allo ...

github
почти 4 года назад

The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.

oracle-oval
почти 16 лет назад

ELSA-2010-0221: squid security and bug fix update (LOW)

2.9 Low

CVSS2