Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-1839
HistorySep 30, 2013 - 12:00 a.m.

CVE-2013-1839

2013-09-3000:00:00
ubuntu.com
ubuntu.com
13

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.902

Percentile

98.8%

The strHdrAcptLangGetItem function in errorpage.cc in Squid 3.2.x before
3.2.9 and 3.3.x before 3.3.3 allows remote attackers to cause a denial of
service (infinite loop and CPU consumption) via a “,” character in an
Accept-Language header.

Notes

Author Note
mdeslaur Doesn’t affect 3.1.x, was introduced in 3.2.0.9

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.902

Percentile

98.8%