PT-2007-2944 · Squid+1 · Squid+2
Publicado
2007-03-21
·
Atualizado
2017-10-11
·
CVE-2007-1560
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Squid versions prior to 2.6.STABLE12
Description
The issue is related to the clientProcessRequest() function, which can be exploited by remote attackers to cause a denial of service. This is achieved through crafted TRACE requests that trigger an assertion error, leading to a daemon crash.
Recommendations
For Squid versions prior to 2.6.STABLE12, update to version 2.6.STABLE12 or later to resolve the issue. As a temporary workaround, consider disabling the clientProcessRequest() function until a patch is available. Restrict access to the TRACE request method to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Red Hat
Squid
Squid Cache