Lucene search

K
nvd[email protected]NVD:CVE-2009-0478
HistoryFeb 08, 2009 - 10:30 p.m.

CVE-2009-0478

2009-02-0822:30:00
CWE-20
web.nvd.nist.gov
1

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.2

Confidence

Low

EPSS

0.951

Percentile

99.3%

Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request with an invalid version number, which triggers a reachable assertion in (1) HttpMsg.c and (2) HttpStatusLine.c.

Affected configurations

NVD
Node
squidsquidMatch2.7.stable1
OR
squidsquidMatch2.7.stable2
OR
squidsquidMatch2.7.stable3
OR
squidsquidMatch2.7.stable4
OR
squidsquidMatch2.7.stable5
OR
squidsquidMatch3.0.stable1
OR
squidsquidMatch3.0.stable2
OR
squidsquidMatch3.0.stable3
OR
squidsquidMatch3.0.stable4
OR
squidsquidMatch3.0.stable5
OR
squidsquidMatch3.0.stable6
OR
squidsquidMatch3.0.stable7
OR
squidsquidMatch3.0.stable8
OR
squidsquidMatch3.0.stable9
OR
squidsquidMatch3.0.stable10
OR
squidsquidMatch3.0.stable11
OR
squidsquidMatch3.0.stable12
OR
squidsquidMatch3.1
OR
squidsquidMatch3.1.0.1
OR
squidsquidMatch3.1.0.2
OR
squidsquidMatch3.1.0.3
OR
squidsquidMatch3.1.0.4

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.2

Confidence

Low

EPSS

0.951

Percentile

99.3%