Executive Summary
Summary | |
---|---|
Title | New adzapper packages fix denial of service |
Informations | |||
---|---|---|---|
Name | DSA-966 | First vendor Publication | 2006-02-09 |
Vendor | Debian | Last vendor Modification | 2006-02-09 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:C) | |||
---|---|---|---|
Cvss Base Score | 7.8 | Attack Range | Network |
Cvss Impact Score | 6.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Thomas Reifferscheid discovered that adzapper, a proxy advertisement zapper add-on, when installed as plugin in squid, the Internet object cache, can consume a lot of CPU resources and hence cause a denial of service on the proxy host. The old stable distribution (woody) does not contain an adzapper package. For the stable distribution (sarge) this problem has been fixed in version 20050316-1sarge1. For the unstable distribution (sid) this problem has been fixed in version 20060115-1. We recommend that you upgrade your adzapper package. |
Original Source
Url : http://www.debian.org/security/2006/dsa-966 |
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2008-01-17 | Name : Debian Security Advisory DSA 966-1 (adzapper) File : nvt/deb_966_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
22900 | Ad Zapping With Squid squid_redirect Crafted URL DoS Ad Zapper for squid contains a flaw that may allow a remote denial of service. The issue is triggered when sending a URL to the squid_redirect script with a large number of forward slashes. This can cause the remote host to consume CPU resources, potentially causing a denial of service. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2006-10-14 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-966.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:34:53 |
|