5

CVE-2009-0478

Exploit
Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request with an invalid version number, which triggers a reachable assertion in (1) HttpMsg.c and (2) HttpStatusLine.c.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Squid ≫ Squid Version 2.7.stable1
Squid ≫ Squid Version 2.7.stable2
Squid ≫ Squid Version 2.7.stable3
Squid ≫ Squid Version 2.7.stable4
Squid ≫ Squid Version 2.7.stable5
Squid ≫ Squid Version 3.0.stable1
Squid ≫ Squid Version 3.0.stable2
Squid ≫ Squid Version 3.0.stable3
Squid ≫ Squid Version 3.0.stable4
Squid ≫ Squid Version 3.0.stable5
Squid ≫ Squid Version 3.0.stable6
Squid ≫ Squid Version 3.0.stable7
Squid ≫ Squid Version 3.0.stable8
Squid ≫ Squid Version 3.0.stable9
Squid ≫ Squid Version 3.0.stable10
Squid ≫ Squid Version 3.0.stable11
Squid ≫ Squid Version 3.0.stable12
Squid ≫ Squid Version 3.1
Squid ≫ Squid Version 3.1.0.1
Squid ≫ Squid Version 3.1.0.2
Squid ≫ Squid Version 3.1.0.3
Squid ≫ Squid Version 3.1.0.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 71.99% 0.994
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html
http://secunia.com/advisories/34467
Vendor Advisory
http://security.gentoo.org/glsa/glsa-200903-38.xml
http://secunia.com/advisories/33731
Vendor Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2009:034
http://www.securityfocus.com/archive/1/500653/100/0/threaded
http://www.securityfocus.com/bid/33604
Patch
Exploit
http://www.securitytracker.com/id?1021684
http://www.squid-cache.org/Advisories/SQUID-2009_1.txt
Vendor Advisory
http://www.squid-cache.org/Versions/v2/2.7/changesets/12432.patch
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=484246
https://www.exploit-db.com/exploits/8021