Candidate: CVE-2009-3700 PublicDate: 2009-10-28 14:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3700 http://www.vupen.com/english/advisories/2009/3013 Description: Buffer overflow in sgLog.c in squidGuard 1.3 and 1.4 allows remote attackers to cause a denial of service (application hang or loss of blocking functionality) via a long URL with many / (slash) characters, related to "emergency mode." Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: jdstrand CVSS: Patches_squidguard: vendor: http://www.debian.org/security/2010/dsa-2040 upstream_squidguard: released (1.2.0-9) dapper_squidguard: released (1.2.0-7ubuntu0.1) hardy_squidguard: released (1.2.0-8.2ubuntu2.1) intrepid_squidguard: needed (reached end-of-life) jaunty_squidguard: released (1.2.0-8.4ubuntu1.0.9.04.1) karmic_squidguard: released (1.2.0-8.4ubuntu1.0.9.10.1) lucid_squidguard: released (1.2.0-8.4ubuntu1.0.10.04.1) devel_squidguard: not-affected (1.2.0-9ubuntu1)