FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2009-2622

This CVE name corresponds to:

Entered Topic
2009-07-27 squid -- several remote denial of service vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2009-2622
Phase Assigned(20090728)

Description

Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 allows remote attackers to cause a denial of service via malformed requests including (1) "missing or mismatched protocol identifier," (2) missing or negative status value," (3) "missing version," or (4) "missing or invalid status number," related to (a) HttpMsg.cc and (b) HttpReply.cc.

References

Source Reference
CONFIRM http://www.squid-cache.org/Advisories/SQUID-2009_2.txt
CONFIRM http://www.squid-cache.org/Versions/v3/3.1/changesets/b9661.patch
MANDRIVA MDVSA-2009:178
MANDRIVA MDVSA-2009:161
BID 35812
SECTRACK 1022607
SECUNIA 36007
VUPEN ADV-2009-2013