CVE-2009-2622: Input Validation
Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 allows remote attackers to cause a denial of service via malformed requests including (1) "missing or mismatched protocol identifier," (2) missing or negative status value," (3) "missing version," or (4) "missing or invalid status number," related to (a) HttpMsg.cc and (b) HttpReply.cc.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2622?
CVE-2009-2622 is categorized as a denial of service vulnerability affecting certain versions of Squid.
How do I fix CVE-2009-2622?
To mitigate CVE-2009-2622, upgrade to a patched version of Squid that addresses this vulnerability.
Which versions of Squid are affected by CVE-2009-2622?
CVE-2009-2622 affects Squid versions 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11.
What type of attacks does CVE-2009-2622 enable?
CVE-2009-2622 allows remote attackers to execute denial of service attacks through malformed requests.
Is CVE-2009-2622 easy to exploit?
CVE-2009-2622 can be exploited relatively easily by sending specially crafted requests to the affected Squid versions.