The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.
| Software | From | Fixed in |
|---|---|---|
| squid-cache / squid | 2.7-stable3 | 2.7-stable3.x |
| squid-cache / squid | 2.7-stable4 | 2.7-stable4.x |
| squid-cache / squid | 2.7 | 2.7.x |