CVE-2009-2621

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
28/07/2009
Last modified:
09/04/2025

Description

Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 does not properly enforce "buffer limits and related bound checks," which allows remote attackers to cause a denial of service via (1) an incomplete request or (2) a request with a large header size, related to (a) HttpMsg.cc and (b) client_side.cc.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:squid-cache:squid:3.0:*:pre1:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:3.0:*:pre2:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:3.0:*:pre3:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:3.0:*:pre4:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:3.0:*:pre5:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:3.0:*:pre6:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:3.0:*:pre7:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:3.0:*:stable1:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:3.0:*:stable10:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:3.0:*:stable11:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:3.0:*:stable12:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:3.0:*:stable13:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:3.0:*:stable14:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:3.0:*:stable15:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:3.0:*:stable2:*:*:*:*:*