Description
The strHdrAcptLangGetItem function in errorpage.cc in Squid 3.2.x before 3.2.9 and 3.3.x before 3.3.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a "," character in an Accept-Language header.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T15:13:33.008Z
Reserved: 2013-02-19T00:00:00.000Z
Link: CVE-2013-1839
No data.
Status : Modified
Published: 2013-09-30T22:55:04.633
Modified: 2026-06-16T23:52:13.047
Link: CVE-2013-1839
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-20
Improper Input Validation