PT-2009-5022 · Squid · Squid+1

Rob Middleton

·

Published

2009-07-28

·

Updated

2009-08-12

·

CVE-2009-2622

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Squid versions 3.0 through 3.0.STABLE16 Squid versions 3.1 through 3.1.0.11
Description The issue allows remote attackers to cause a denial of service via malformed requests, including missing or mismatched protocol identifiers, missing or negative status values, missing versions, or missing or invalid status numbers. This is related to the HttpMsg.cc and HttpReply.cc components.
Recommendations For Squid versions 3.0 through 3.0.STABLE16, update to a version later than 3.0.STABLE16 to resolve the issue. For Squid versions 3.1 through 3.1.0.11, update to a version later than 3.1.0.11 to resolve the issue.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2622
DSA-1843-1
DSA-1843-2

Affected Products

Squid
Squid Cache