Oval Definition:oval:org.opensuse.security:def:20092855
Revision Date:2022-05-20Version:1
Title:CVE-2009-2855
Description:

The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2009-2855
Mitre CVE-2009-2855
SUSE CVE-2009-2855
SUSE-SR:2010:007
SUSE-SR:2010:007
Platform(s):Open Enterprise Server
openSUSE 11.0
openSUSE 11.1
openSUSE 11.2
SUSE CORE 9 for AMD64 and Intel EM64T
SUSE Linux Enterprise Desktop 10 SP3 for AMD64 and Intel EM64T
SUSE Linux Enterprise Desktop 10 SP3 for x86
SUSE Linux Enterprise SDK 10 SP3
SUSE Linux Enterprise Server 10 SP3
SUSE Linux Enterprise Server 11
SUSE Linux Enterprise Server 11 GA
SUSE Linux Enterprise Server 11 SP1
SUSE Linux Enterprise Server 11 SP2
SUSE Linux Enterprise Server 11 SP3
SUSE Linux Enterprise Server 11 SP4
SUSE Linux Enterprise Server for SAP 10 SP2
SUSE Linux Enterprise Server for SAP 10 SP3
SUSE Linux Enterprise Server for SAP Applications 11
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Server 11 is installed
  • AND squid-2.7.STABLE5-2.4.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 11 SP3 is installed
  • AND squid-2.7.STABLE5-2.12.12 is installed
  • Definition Synopsis
  • Release Information
  • sles10-sp2-sap is installed
  • AND squid less than 2.5.STABLE12-18.13.982.2.2
  • OR Package Information
  • sles10-sp3 is installed
  • AND squid less than 2.5.STABLE12-18.13.982.2.1
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 11 is installed
  • AND squid-2.7.STABLE5-2.4.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 11 SP2 is installed
  • AND squid-2.7.STABLE5-2.10.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 11 SP3 is installed
  • AND squid-2.7.STABLE5-2.12.12.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 11 SP4 is installed
  • AND squid-2.7.STABLE5-2.12.16.1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 11 is installed
  • AND squid-2.7.STABLE5-2.4.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 11 SP3 is installed
  • AND squid-2.7.STABLE5-2.12.12.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 11 SP4 is installed
  • AND squid-2.7.STABLE5-2.12.16.1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 11 is installed
  • AND squid-2.7.STABLE5-2.4 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 11 SP1 is installed
  • AND squid-2.7.STABLE5-2.4 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 11 SP2 is installed
  • AND squid-2.7.STABLE5-2.10 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 11 SP3 is installed
  • AND squid-2.7.STABLE5-2.12.12 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 11 SP4 is installed
  • AND squid-2.7.STABLE5-2.12.16 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server 11 SP1 is installed
  • AND squid-2.7.STABLE5-2.4.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 11 SP2 is installed
  • AND squid-2.7.STABLE5-2.10.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 11 SP3 is installed
  • AND squid-2.7.STABLE5-2.12.12.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 11 SP4 is installed
  • AND squid-2.7.STABLE5-2.12.16.1 is installed
  • OR Package Information
  • SUSE Linux Enterprise Server 11 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 11 is installed
  • AND squid-2.7.STABLE5-2.4.1 is installed
  • BACK