PT-2007-2944 · Squid+1 · Squid+2

Publicado

2007-03-21

·

Atualizado

2017-10-11

·

CVE-2007-1560

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Squid versions prior to 2.6.STABLE12
Description The issue is related to the clientProcessRequest() function, which can be exploited by remote attackers to cause a denial of service. This is achieved through crafted TRACE requests that trigger an assertion error, leading to a daemon crash.
Recommendations For Squid versions prior to 2.6.STABLE12, update to version 2.6.STABLE12 or later to resolve the issue. As a temporary workaround, consider disabling the clientProcessRequest() function until a patch is available. Restrict access to the TRACE request method to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-1560
RHSA-2007:0131
RHSA-2007_0131

Produtos afetados

Red Hat
Squid
Squid Cache