PT-2007-2944 · Squid+1 · Squid+2
Published
2007-03-21
·
Updated
2017-10-11
·
CVE-2007-1560
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Squid versions prior to 2.6.STABLE12
Description
The issue is related to the clientProcessRequest() function, which can be exploited by remote attackers to cause a denial of service. This is achieved through crafted TRACE requests that trigger an assertion error, leading to a daemon crash.
Recommendations
For Squid versions prior to 2.6.STABLE12, update to version 2.6.STABLE12 or later to resolve the issue. As a temporary workaround, consider disabling the clientProcessRequest() function until a patch is available. Restrict access to the TRACE request method to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat
Squid
Squid Cache