PT-2009-6053 · Squid+1 · Squid+1
Published
2009-10-28
·
Updated
2024-06-15
·
CVE-2009-3826
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
squidGuard version 1.4
Description
The issue is related to multiple buffer overflows that allow remote attackers to bypass intended URL blocking via a long URL. This is connected to the relationship between buffer sizes in squidGuard and Squid, as well as redirect URLs containing information about originally requested URLs.
Recommendations
For squidGuard version 1.4, consider restricting access to long URLs as a temporary workaround until a patch is available. Additionally, review and adjust buffer size configurations to prevent overflows.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Squid
Squidguard