Description
The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.
CVSS vector
AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9Complexity: Low
Confidentiality: None
Integrity: None
Affected Packages2 packages
🔴Vulnerability Details
3GHSAGHSA-7hrp-6jq3-pm4q: The strListGetItem function in src/HttpHeaderTools↗2022-05-02 ▶ CVEListCVE-2009-2855: The strListGetItem function in src/HttpHeaderTools↗2009-08-18 ▶ OSVCVE-2009-2855: The strListGetItem function in src/HttpHeaderTools↗2009-08-18 ▶ 📋Vendor Advisories
3UbuntuSquid vulnerabilities↗2010-02-16 ▶ Red Hatsquid: DoS (100% CPU use) while processing certain external ACL helper HTTP headers↗2009-06-28 ▶ DebianCVE-2009-2855: squid - The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote ...↗2009 ▶ 💬Community
2BugzillaCVE-2009-2855 squid: DoS (100% CPU use) while processing certain external ACL helper HTTP headers↗2009-08-19 ▶ Bugzillasquid DoS in external auth header parser↗2009-07-06 ▶