PT-2009-6053 · Squid+1 · Squid+1
Publicado
2009-10-28
·
Atualizado
2024-06-15
·
CVE-2009-3826
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
squidGuard version 1.4
Description
The issue is related to multiple buffer overflows that allow remote attackers to bypass intended URL blocking via a long URL. This is connected to the relationship between buffer sizes in squidGuard and Squid, as well as redirect URLs containing information about originally requested URLs.
Recommendations
For squidGuard version 1.4, consider restricting access to long URLs as a temporary workaround until a patch is available. Additionally, review and adjust buffer size configurations to prevent overflows.
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Squid
Squidguard