CVE-2009-2855
squid squid3 - denial of service
EPSS 36.7%
描述
The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.
如何修補 CVE-2009-2855
要修補 CVE-2009-2855,請將受影響套件升級到下列已修補版本。
- Debian/squid—升級至 2.7.STABLE7-1 或更新版本
- Debian/squid—升級至 2.6.5-6etch5 或更新版本
- Debian/squid3—升級至 3.0.PRE5-5+etch2 或更新版本
CVE-2009-2855 正在被利用嗎?
中等 — EPSS 為 36.7%,可持續追蹤但非最高優先。
受影響套件(3)
- from 0, < 2.7.STABLE7-1
- from 0, < 2.6.5-6etch5
- from 0, < 3.0.PRE5-5+etch2