CVE-2009-0478
Estado: ModificadaMedia (5)—💥 Exploit
Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request with an invalid version number, which triggers a reachable assertion in (1) HttpMsg.c and (2) HttpStatusLine.c.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 72%
- Percentil entre todas las CVEs puntuadas: 99
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
💥 Exploits públicos
Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.
- Publicado en Exploit-DB · Squid < 3.1 5 - HTTP Version Number Parsing Denial of Service (9/2/2009)
Tecnologías afectadas (1)
CWE
- CWE-20
Referencias
- http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html
- http://secunia.com/advisories/33731
- http://secunia.com/advisories/34467
- http://security.gentoo.org/glsa/glsa-200903-38.xml
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:034
- http://www.securityfocus.com/archive/1/500653/100/0/threaded
- http://www.securityfocus.com/bid/33604
- http://www.securitytracker.com/id?1021684
- http://www.squid-cache.org/Advisories/SQUID-2009_1.txt
- http://www.squid-cache.org/Versions/v2/2.7/changesets/12432.patch
- https://bugzilla.redhat.com/show_bug.cgi?id=484246
- https://www.exploit-db.com/exploits/8021
- http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html
- http://secunia.com/advisories/33731
- http://secunia.com/advisories/34467
- http://security.gentoo.org/glsa/glsa-200903-38.xml
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:034
- http://www.securityfocus.com/archive/1/500653/100/0/threaded
- http://www.securityfocus.com/bid/33604
- http://www.securitytracker.com/id?1021684
- http://www.squid-cache.org/Advisories/SQUID-2009_1.txt
- http://www.squid-cache.org/Versions/v2/2.7/changesets/12432.patch
- https://bugzilla.redhat.com/show_bug.cgi?id=484246
- https://www.exploit-db.com/exploits/8021
JSON original (NVD)
Mostrar
{
"id": "CVE-2009-0478",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2009-02-08T22:30:00.360",
"references": [
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/33731",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/34467",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://security.gentoo.org/glsa/glsa-200903-38.xml",
"source": "cve@mitre.org"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:034",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/500653/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/33604",
"tags": [
"Exploit",
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1021684",
"source": "cve@mitre.org"
},
{
"url": "http://www.squid-cache.org/Advisories/SQUID-2009_1.txt",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.squid-cache.org/Versions/v2/2.7/changesets/12432.patch",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=484246",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/8021",
"source": "cve@mitre.org"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00000.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/33731",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/34467",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://security.gentoo.org/glsa/glsa-200903-38.xml",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2009:034",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/500653/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/33604",
"tags": [
"Exploit",
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1021684",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.squid-cache.org/Advisories/SQUID-2009_1.txt",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.squid-cache.org/Versions/v2/2.7/changesets/12432.patch",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=484246",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/8021",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request with an invalid version number, which triggers a reachable assertion in (1) HttpMsg.c and (2) HttpStatusLine.c."
},
{
"lang": "es",
"value": "Squid versiones 2.7 hasta 2.7.STABLE5, versiones 3.0 hasta 3.0.STABLE12 y versiones 3.1 hasta 3.1.0.4, permiten a los atacantes remotos causar una denegación de servicio por medio de una petición HTTP con un número de versión no válido, lo que desencadena una aserción accesible en los archivos (1) HttpMsg.c y (2) HttpStatusLine.c."
}
],
"lastModified": "2026-06-16T23:05:07.550",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:squid:squid:2.7.stable1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1CDD4129-3F89-4833-8789-4568CAE3B646"
},
{
"criteria": "cpe:2.3:a:squid:squid:2.7.stable2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FFF2ED3A-B88A-49EE-9565-56C726447882"
},
{
"criteria": "cpe:2.3:a:squid:squid:2.7.stable3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "42579A3F-EDD8-44F7-9436-1B386FDC604E"
},
{
"criteria": "cpe:2.3:a:squid:squid:2.7.stable4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C689CFA4-A9F3-4B8B-80CB-F948E8C32C0D"
},
{
"criteria": "cpe:2.3:a:squid:squid:2.7.stable5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E503C019-4E96-4D4F-B9BD-327E3C22DE52"
},
{
"criteria": "cpe:2.3:a:squid:squid:3.0.stable1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9D53774A-4523-4C9F-8FDF-BF39C4F32C0A"
},
{
"criteria": "cpe:2.3:a:squid:squid:3.0.stable2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CBA0CA70-79A0-4AC6-ADE3-99DCE8FB09BE"
},
{
"criteria": "cpe:2.3:a:squid:squid:3.0.stable3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E4048B18-219C-4D23-979B-C32A4F84E088"
},
{
"criteria": "cpe:2.3:a:squid:squid:3.0.stable4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4CBD6F80-63F1-4B6D-BBCD-240D8A18C429"
},
{
"criteria": "cpe:2.3:a:squid:squid:3.0.stable5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "60A83314-4628-4352-BE10-89ED4B228E34"
},
{
"criteria": "cpe:2.3:a:squid:squid:3.0.stable6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "81FD6F1C-ECE2-4ADA-8230-49500AE0AB32"
},
{
"criteria": "cpe:2.3:a:squid:squid:3.0.stable7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0B7A5792-DAD0-4E84-90EB-E92873DB763C"
},
{
"criteria": "cpe:2.3:a:squid:squid:3.0.stable8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7F2786AA-F9B6-4825-9C2E-9548D6D2A3F3"
},
{
"criteria": "cpe:2.3:a:squid:squid:3.0.stable9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2BB49168-03B3-43D5-9076-6FE206EF42A4"
},
{
"criteria": "cpe:2.3:a:squid:squid:3.0.stable10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D6CF222F-1A8E-4351-BBD4-5BC39B5BF2FB"
},
{
"criteria": "cpe:2.3:a:squid:squid:3.0.stable11:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "38092277-47D4-4B83-BF32-DE595CDE7B2E"
},
{
"criteria": "cpe:2.3:a:squid:squid:3.0.stable12:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C6ED346B-D762-481D-92FA-260C2C5A915A"
},
{
"criteria": "cpe:2.3:a:squid:squid:3.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "73060F28-ABCE-4428-8F12-772E4D312DC2"
},
{
"criteria": "cpe:2.3:a:squid:squid:3.1.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6A006818-7901-4391-BFF7-9AD1AF8DAFCF"
},
{
"criteria": "cpe:2.3:a:squid:squid:3.1.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4BF28EA4-2847-4176-81C1-C7A2007D14E5"
},
{
"criteria": "cpe:2.3:a:squid:squid:3.1.0.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1FAD9B4B-0856-458B-AB21-15D0420A7F67"
},
{
"criteria": "cpe:2.3:a:squid:squid:3.1.0.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "54E9F64C-363B-4702-996F-14F66450D6B2"
}
],
"operator": "OR"
}
]
}
],
"vendorComments": [
{
"comment": "Not vulnerable. This issue did not affect the version of Squid as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.",
"lastModified": "2009-02-09T00:00:00",
"organization": "Red Hat"
}
],
"sourceIdentifier": "cve@mitre.org"
}