CVE-2009-3700
squidguard - several vulnerabilities
EPSS 3.8%
Description
Buffer overflow in sgLog.c in squidGuard 1.3 and 1.4 allows remote attackers to cause a denial of service (application hang or loss of blocking functionality) via a long URL with many / (slash) characters, related to "emergency mode."
How to fix CVE-2009-3700
To remediate CVE-2009-3700, upgrade the affected package to a fixed version below.
- Debian/squidguard—upgrade to 1.2.0-9 or later
- Debian/squidguard—upgrade to 1.2.0-8.4+lenny1 or later
Is CVE-2009-3700 being exploited?
Low — EPSS is 3.8%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 1.2.0-9
- from 0, < 1.2.0-8.4+lenny1