Squid.StrListGetItem.DoS
Description
The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.
Affected Products
Squid Web Proxy Cache 3.1 5 and previous versions.
Impact
Denial of Service.
Recommended Actions
Apply patch:
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |
Version Updates
Date | Version | Detail |
---|---|---|
2018-10-16 | 13.473 | Sig Added |