CVE-2009-2855

The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:squid-cache:squid:2.7:*:*:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:2.7:stable3:*:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:2.7:stable4:*:*:*:*:*:*

History

No history.

Information

Published : 2009-08-18 21:00

Updated : 2024-02-04 17:33


NVD link : CVE-2009-2855

Mitre link : CVE-2009-2855

CVE.ORG link : CVE-2009-2855


JSON object : View

Products Affected

squid-cache

  • squid
CWE
CWE-20

Improper Input Validation