PT-2006-1135 · Adzapper · Adzapper

Thomas Reifferscheid

·

Published

2006-02-13

·

Updated

2017-07-20

·

CVE-2006-0046

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: adzapper versions prior to 2006-01-29
Description: The issue allows remote attackers to cause a denial of service, specifically CPU consumption, by exploiting the squid redirect script in adzapper. This can be achieved by sending a URL with a large number of trailing / (forward slashes), potentially leading to inefficient regular expressions.
Recommendations: For versions prior to 2006-01-29, consider updating to a version released after this date to resolve the issue. As a temporary workaround, restrict access to the squid redirect script to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0046
DSA-966-1

Affected Products

Adzapper