The strListGetItem function in src/HttpHeaderTools.c in...
Moderate severity
Unreviewed
Published
May 2, 2022
to the GitHub Advisory Database
•
Updated Apr 9, 2025
Description
Published by the National Vulnerability Database
Aug 18, 2009
Published to the GitHub Advisory Database
May 2, 2022
Last updated
Apr 9, 2025
The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.
References