MEDIUM
squidGuard: buffer overflow in sgLog.c (CVE-2009-3700) and two URL filter bypass issues (CVE-2009-3826)
Published Oct 28, 2009
5.0
MEDIUMCVSS 2.0
EPSS 3.83%
Description
Multiple buffer overflows in squidGuard 1.4 allow remote attackers to bypass intended URL blocking via a long URL, related to (1) the relationship between a certain buffer size in squidGuard and a certain buffer size in Squid and (2) a redirect URL that contains information about the originally requested URL.
Affected products
No data.
- 1.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (16)
- http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/37107 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/39679 third-party-advisoryx_refsource_SECUNIA
- http://securitytracker.com/id?1023079 vdb-entryx_refsource_SECTRACK
- http://www.debian.org/security/2010/dsa-2040 vendor-advisoryx_refsource_DEBIAN
- http://www.osvdb.org/59164 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/archive/1/507440/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/36800 vdb-entryx_refsource_BIDPatch
- http://www.squidguard.org/Downloads/Patches/1.4/Readme.Patch-20091019 x_refsource_CONFIRMVendor Advisory
- http://www.vupen.com/english/advisories/2009/3013 vdb-entryx_refsource_VUPENPatchVendor Advisory
- http://www.vupen.com/english/advisories/2010/1043 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2009-3826 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=530862 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53922 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2009-3826
- https://www.cve.org/CVERecord?id=CVE-2009-3826
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 28, 2009
Updated Aug 7, 2024
Reserved Oct 28, 2009
Link CVE-2009-3826
CISA Vulnrichment
Updated n/a