First published: Tue Jul 28 2009(Updated: )
Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 does not properly enforce "buffer limits and related bound checks," which allows remote attackers to cause a denial of service via (1) an incomplete request or (2) a request with a large header size, related to (a) HttpMsg.cc and (b) client_side.cc.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Squid Web Proxy Cache | =3.0-rc4 | |
Squid Web Proxy Cache | =3.0 | |
Squid Web Proxy Cache | =3.0 | |
Squid Web Proxy Cache | =3.0 | |
Squid Web Proxy Cache | =3.0 | |
Squid Web Proxy Cache | =3.0 | |
Squid Web Proxy Cache | =3.0 | |
Squid Web Proxy Cache | =3.1.0.3 | |
Squid Web Proxy Cache | =3.1.0.1 | |
Squid Web Proxy Cache | =3.0 | |
Squid Web Proxy Cache | =3.0 | |
Squid Web Proxy Cache | =3.0 | |
Squid Web Proxy Cache | =3.0-rc1 | |
Squid Web Proxy Cache | =3.0 | |
Squid Web Proxy Cache | =3.0 | |
Squid Web Proxy Cache | =3.1.0.2 | |
Squid Web Proxy Cache | =3.0 | |
Squid Web Proxy Cache | =3.0 | |
Squid Web Proxy Cache | =3.1.0.4 | |
Squid Web Proxy Cache | =3.0 | |
Squid Web Proxy Cache | =3.0 | |
Squid Web Proxy Cache | =3.1 | |
Squid Web Proxy Cache | =3.0 | |
Squid Web Proxy Cache | =3.0 | |
Squid Web Proxy Cache | =3.0 | |
Squid Web Proxy Cache | =3.0 | |
Squid Web Proxy Cache | =3.0 | |
Squid Web Proxy Cache | =3.0 | |
Squid Web Proxy Cache | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2621 is classified as a denial of service vulnerability which can severely impact the availability of the affected systems.
To fix CVE-2009-2621, upgrade to a patched version of Squid that addresses the buffer limits and bound checks.
CVE-2009-2621 affects Squid versions 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11.
CVE-2009-2621 can be exploited via incomplete requests or requests with excessively large header sizes.
CVE-2009-2621 relates specifically to issues in HttpMsg.cc and client_sid within Squid.