FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2009-2621

This CVE name corresponds to:

Entered Topic
2009-07-27 squid -- several remote denial of service vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2009-2621
Phase Assigned(20090728)

Description

Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 does not properly enforce "buffer limits and related bound checks," which allows remote attackers to cause a denial of service via (1) an incomplete request or (2) a request with a large header size, related to (a) HttpMsg.cc and (b) client_side.cc.

References

Source Reference
CONFIRM http://www.squid-cache.org/Advisories/SQUID-2009_2.txt
CONFIRM http://www.squid-cache.org/Versions/v3/3.1/changesets/b9654.patch
MANDRIVA MDVSA-2009:178
MANDRIVA MDVSA-2009:161
BID 35812
SECTRACK 1022607
SECUNIA 36007
VUPEN ADV-2009-2013