Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 does not properly enforce "buffer limits and related bound checks," which allows remote attackers to cause a denial of service via (1) an incomplete request or (2) a request with a large header size, related to (a) HttpMsg.cc and (b) client_side.cc.
2009-07-28T17:30:01.077
2025-04-09T00:30:58.490
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | squid-cache | squid | 3.0 | Yes |
Application | squid-cache | squid | 3.0 | Yes |
Application | squid-cache | squid | 3.0 | Yes |
Application | squid-cache | squid | 3.0 | Yes |
Application | squid-cache | squid | 3.0 | Yes |
Application | squid-cache | squid | 3.0 | Yes |
Application | squid-cache | squid | 3.0 | Yes |
Application | squid-cache | squid | 3.0 | Yes |
Application | squid-cache | squid | 3.0 | Yes |
Application | squid-cache | squid | 3.0 | Yes |
Application | squid-cache | squid | 3.0 | Yes |
Application | squid-cache | squid | 3.0 | Yes |
Application | squid-cache | squid | 3.0 | Yes |
Application | squid-cache | squid | 3.0 | Yes |
Application | squid-cache | squid | 3.0 | Yes |
Application | squid-cache | squid | 3.0 | Yes |
Application | squid-cache | squid | 3.0 | Yes |
Application | squid-cache | squid | 3.0 | Yes |
Application | squid-cache | squid | 3.0 | Yes |
Application | squid-cache | squid | 3.0 | Yes |
Application | squid-cache | squid | 3.0 | Yes |
Application | squid-cache | squid | 3.0 | Yes |
Application | squid-cache | squid | 3.0 | Yes |
Application | squid-cache | squid | 3.0 | Yes |
Application | squid-cache | squid | 3.1 | Yes |
Application | squid-cache | squid | 3.1.0.1 | Yes |
Application | squid-cache | squid | 3.1.0.2 | Yes |
Application | squid-cache | squid | 3.1.0.3 | Yes |
Application | squid-cache | squid | 3.1.0.4 | Yes |