HTTP: Squid strListGetItem Denial of Service

This signature detects attempts to exploit a known vulnerability against Squid Proxy. A successful attack can result in a denial-of-service condition.

Extended Description

Squid is prone to a remote denial-of-service vulnerability because the proxy server fails to properly parse certain external authentication headers that contain comma delimiters. Successfully exploiting this issue allows remote attackers to trigger an infinite loop and consume system resources, denying further service to legitimate users.

Affected Products

Debian linux

Short Name
HTTP:PROXY:SQUID-STRLISTGETITEM
Severity
Minor
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
CVE-2009-2855 Denial Service Squid bid:36091 of strListGetItem
Release Date
09/30/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Red_hat

Suse

Gentoo

Squid

Turbolinux

Ubuntu

Mandriva

Debian

CVSS Score

5.0

Found a potential security threat?