PT-2007-2944 · Squid+1 · Squid+2

Published

2007-03-21

·

Updated

2017-10-11

·

CVE-2007-1560

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Squid versions prior to 2.6.STABLE12
Description The issue is related to the clientProcessRequest() function, which can be exploited by remote attackers to cause a denial of service. This is achieved through crafted TRACE requests that trigger an assertion error, leading to a daemon crash.
Recommendations For Squid versions prior to 2.6.STABLE12, update to version 2.6.STABLE12 or later to resolve the issue. As a temporary workaround, consider disabling the clientProcessRequest() function until a patch is available. Restrict access to the TRACE request method to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1560
RHSA-2007:0131
RHSA-2007_0131

Affected Products

Red Hat
Squid
Squid Cache