CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
COMPLETE
AV:N/AC:L/Au:N/C:N/I:N/A:C
EPSS
Percentile
98.8%
The strHdrAcptLangGetItem function in errorpage.cc in Squid 3.2.x before
3.2.9 and 3.3.x before 3.3.3 allows remote attackers to cause a denial of
service (infinite loop and CPU consumption) via a “,” character in an
Accept-Language header.
Author | Note |
---|---|
mdeslaur | Doesn’t affect 3.1.x, was introduced in 3.2.0.9 |