CVE-2007-6239
The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial of service (crash) via unknown vectors related to HTTP headers and an Array memory leak during requests for cached…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 26.7%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial of service (crash) via unknown vectors related to HTTP headers and an Array memory leak during requests for cached objects.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 26.66% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- squid/squid web proxy cache
- Source
- secalert@redhat.com
References
- http://bugs.gentoo.org/show_bug.cgi?id=201209
- http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00002.html
- http://secunia.com/advisories/27910Patch, Vendor Advisory
- http://secunia.com/advisories/28091Vendor Advisory
- http://secunia.com/advisories/28109Vendor Advisory
- http://secunia.com/advisories/28350Vendor Advisory
- http://secunia.com/advisories/28381Vendor Advisory
- http://secunia.com/advisories/28403Vendor Advisory
- http://secunia.com/advisories/28412Vendor Advisory
- http://secunia.com/advisories/28814Vendor Advisory
- http://secunia.com/advisories/34467Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200801-05.xml
- http://security.gentoo.org/glsa/glsa-200903-38.xml
- http://www.debian.org/security/2008/dsa-1482Patch
- http://www.kb.cert.org/vuls/id/232881US Government Resource
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:002
- http://www.redhat.com/support/errata/RHSA-2007-1130.htmlPatch
- http://www.securityfocus.com/bid/26687Patch
- http://www.securitytracker.com/id?1019036
- http://www.squid-cache.org/Advisories/SQUID-2007_2.txtPatch, Vendor Advisory
- http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patchExploit, Vendor Advisory
- http://www.ubuntu.com/usn/usn-565-1
- http://www.vupen.com/english/advisories/2007/4066Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=410181
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10915
- https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00497.html
- https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00507.html
- http://bugs.gentoo.org/show_bug.cgi?id=201209
- http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00002.html
- http://secunia.com/advisories/27910Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.