PT-2006-1135 · Adzapper · Adzapper
Thomas Reifferscheid
·
Published
2006-02-13
·
Updated
2017-07-20
·
CVE-2006-0046
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
adzapper versions prior to 2006-01-29
Description:
The issue allows remote attackers to cause a denial of service, specifically CPU consumption, by exploiting the squid redirect script in adzapper. This can be achieved by sending a URL with a large number of trailing / (forward slashes), potentially leading to inefficient regular expressions.
Recommendations:
For versions prior to 2006-01-29, consider updating to a version released after this date to resolve the issue. As a temporary workaround, restrict access to the squid redirect script to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Adzapper