CVE-2009-2855

The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:squid-cache:squid:2.7:*:*:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:2.7:stable3:*:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:2.7:stable4:*:*:*:*:*:*

History

07 Nov 2023, 02:04

Type Values Removed Values Added
References
  • {'url': 'http://bugs.debian.org/cgi-bin/bugreport.cgi?msg=31;filename=diff;att=1;bug=534982', 'name': 'http://bugs.debian.org/cgi-bin/bugreport.cgi?msg=31;filename=diff;att=1;bug=534982', 'tags': [], 'refsource': 'MISC'}
  • () http://bugs.debian.org/cgi-bin/bugreport.cgi?msg=31%3Bfilename=diff%3Batt=1%3Bbug=534982 -

Information

Published : 2009-08-18 21:00

Updated : 2023-12-10 10:51


NVD link : CVE-2009-2855

Mitre link : CVE-2009-2855

CVE.ORG link : CVE-2009-2855


JSON object : View

Products Affected

squid-cache

  • squid
CWE
CWE-20

Improper Input Validation