CVE-2010-0639
The htcpHandleTstRequest function in htcp.c in Squid 2.x before 2.6.STABLE24 and 2.7 before 2.7.STABLE8, and htcp.cc in 3.0 before 3.0.STABLE24, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via crafted…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 30.6%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The htcpHandleTstRequest function in htcp.c in Squid 2.x before 2.6.STABLE24 and 2.7 before 2.7.STABLE8, and htcp.cc in 3.0 before 3.0.STABLE24, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via crafted packets to the HTCP port.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 30.56% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- squid-cache/squid
- Source
- cve@mitre.org
References
- http://bugs.squid-cache.org/show_bug.cgi?id=2858
- http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035961.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-March/037159.html
- http://osvdb.org/62297
- http://secunia.com/advisories/38812Vendor Advisory
- http://www.securityfocus.com/bid/38212
- http://www.securitytracker.com/id?1023587
- http://www.squid-cache.org/Advisories/SQUID-2010_2.txtVendor Advisory
- http://www.squid-cache.org/Versions/v2/2.7/changesets/12600.patchPatch
- http://www.squid-cache.org/Versions/v3/3.0/changesets/3.0-ADV-2010_2.patchPatch
- http://www.vupen.com/english/advisories/2010/0371Vendor Advisory
- http://www.vupen.com/english/advisories/2010/0603Vendor Advisory
- http://bugs.squid-cache.org/show_bug.cgi?id=2858
- http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035961.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-March/037159.html
- http://osvdb.org/62297
- http://secunia.com/advisories/38812Vendor Advisory
- http://www.securityfocus.com/bid/38212
- http://www.securitytracker.com/id?1023587
- http://www.squid-cache.org/Advisories/SQUID-2010_2.txtVendor Advisory
- http://www.squid-cache.org/Versions/v2/2.7/changesets/12600.patchPatch
- http://www.squid-cache.org/Versions/v3/3.0/changesets/3.0-ADV-2010_2.patchPatch
- http://www.vupen.com/english/advisories/2010/0371Vendor Advisory
- http://www.vupen.com/english/advisories/2010/0603Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.