5

CVE-2009-2622

Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 allows remote attackers to cause a denial of service via malformed requests including (1) "missing or mismatched protocol identifier," (2) missing or negative status value," (3) "missing version," or (4) "missing or invalid status number," related to (a) HttpMsg.cc and (b) HttpReply.cc.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Squid-cache ≫ Squid Version 3.0 Edition pre1
Squid-cache ≫ Squid Version 3.0 Edition pre2
Squid-cache ≫ Squid Version 3.0 Edition pre3
Squid-cache ≫ Squid Version 3.0 Edition pre4
Squid-cache ≫ Squid Version 3.0 Edition pre5
Squid-cache ≫ Squid Version 3.0 Edition pre6
Squid-cache ≫ Squid Version 3.0 Edition pre7
Squid-cache ≫ Squid Version 3.0 Edition stable1
Squid-cache ≫ Squid Version 3.0 Edition stable10
Squid-cache ≫ Squid Version 3.0 Edition stable11
Squid-cache ≫ Squid Version 3.0 Edition stable12
Squid-cache ≫ Squid Version 3.0 Edition stable13
Squid-cache ≫ Squid Version 3.0 Edition stable14
Squid-cache ≫ Squid Version 3.0 Edition stable15
Squid-cache ≫ Squid Version 3.0 Edition stable2
Squid-cache ≫ Squid Version 3.0 Edition stable3
Squid-cache ≫ Squid Version 3.0 Edition stable4
Squid-cache ≫ Squid Version 3.0 Edition stable5
Squid-cache ≫ Squid Version 3.0 Edition stable6
Squid-cache ≫ Squid Version 3.0 Edition stable7
Squid-cache ≫ Squid Version 3.0 Edition stable8
Squid-cache ≫ Squid Version 3.0 Edition stable9
Squid-cache ≫ Squid Version 3.0 Update rc1 Edition stable11
Squid-cache ≫ Squid Version 3.0 Update rc4
Squid-cache ≫ Squid Version 3.1
Squid-cache ≫ Squid Version 3.1.0.1
Squid-cache ≫ Squid Version 3.1.0.2
Squid-cache ≫ Squid Version 3.1.0.3
Squid-cache ≫ Squid Version 3.1.0.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 56.91% 0.989
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://secunia.com/advisories/36007
http://www.mandriva.com/security/advisories?name=MDVSA-2009:161
http://www.mandriva.com/security/advisories?name=MDVSA-2009:178
http://www.securityfocus.com/bid/35812
http://www.securitytracker.com/id?1022607
http://www.squid-cache.org/Advisories/SQUID-2009_2.txt
Vendor Advisory
http://www.vupen.com/english/advisories/2009/2013
http://www.squid-cache.org/Versions/v3/3.1/changesets/b9661.patch
Patch
Vendor Advisory