5

CVE-2009-2621

Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 does not properly enforce "buffer limits and related bound checks," which allows remote attackers to cause a denial of service via (1) an incomplete request or (2) a request with a large header size, related to (a) HttpMsg.cc and (b) client_side.cc.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Squid-cache ≫ Squid Version 3.0 Edition pre1
Squid-cache ≫ Squid Version 3.0 Edition pre2
Squid-cache ≫ Squid Version 3.0 Edition pre3
Squid-cache ≫ Squid Version 3.0 Edition pre4
Squid-cache ≫ Squid Version 3.0 Edition pre5
Squid-cache ≫ Squid Version 3.0 Edition pre6
Squid-cache ≫ Squid Version 3.0 Edition pre7
Squid-cache ≫ Squid Version 3.0 Edition stable1
Squid-cache ≫ Squid Version 3.0 Edition stable10
Squid-cache ≫ Squid Version 3.0 Edition stable11
Squid-cache ≫ Squid Version 3.0 Edition stable12
Squid-cache ≫ Squid Version 3.0 Edition stable13
Squid-cache ≫ Squid Version 3.0 Edition stable14
Squid-cache ≫ Squid Version 3.0 Edition stable15
Squid-cache ≫ Squid Version 3.0 Edition stable2
Squid-cache ≫ Squid Version 3.0 Edition stable3
Squid-cache ≫ Squid Version 3.0 Edition stable4
Squid-cache ≫ Squid Version 3.0 Edition stable5
Squid-cache ≫ Squid Version 3.0 Edition stable6
Squid-cache ≫ Squid Version 3.0 Edition stable7
Squid-cache ≫ Squid Version 3.0 Edition stable8
Squid-cache ≫ Squid Version 3.0 Edition stable9
Squid-cache ≫ Squid Version 3.0 Update rc1 Edition stable11
Squid-cache ≫ Squid Version 3.0 Update rc4
Squid-cache ≫ Squid Version 3.1
Squid-cache ≫ Squid Version 3.1.0.1
Squid-cache ≫ Squid Version 3.1.0.2
Squid-cache ≫ Squid Version 3.1.0.3
Squid-cache ≫ Squid Version 3.1.0.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 23.05% 0.975
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://secunia.com/advisories/36007
http://www.mandriva.com/security/advisories?name=MDVSA-2009:161
http://www.mandriva.com/security/advisories?name=MDVSA-2009:178
http://www.securityfocus.com/bid/35812
http://www.securitytracker.com/id?1022607
http://www.squid-cache.org/Advisories/SQUID-2009_2.txt
Vendor Advisory
http://www.squid-cache.org/Versions/v3/3.1/changesets/b9654.patch
Patch
http://www.vupen.com/english/advisories/2009/2013