5

CVE-2009-0478

Exploit

Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request with an invalid version number, which triggers a reachable assertion in (1) HttpMsg.c and (2) HttpStatusLine.c.

Data is provided by the National Vulnerability Database (NVD)
SquidSquid Version2.7.stable1
SquidSquid Version2.7.stable2
SquidSquid Version2.7.stable3
SquidSquid Version2.7.stable4
SquidSquid Version2.7.stable5
SquidSquid Version3.0.stable1
SquidSquid Version3.0.stable2
SquidSquid Version3.0.stable3
SquidSquid Version3.0.stable4
SquidSquid Version3.0.stable5
SquidSquid Version3.0.stable6
SquidSquid Version3.0.stable7
SquidSquid Version3.0.stable8
SquidSquid Version3.0.stable9
SquidSquid Version3.0.stable10
SquidSquid Version3.0.stable11
SquidSquid Version3.0.stable12
SquidSquid Version3.1
SquidSquid Version3.1.0.1
SquidSquid Version3.1.0.2
SquidSquid Version3.1.0.3
SquidSquid Version3.1.0.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 77.41% 0.989
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.