>> Squid "sslConnectTimeout()" Remote Denial of Service Vulnerability
Title : Squid "sslConnectTimeout()" Remote Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2005-1622 CVE ID : CVE-2005-2796 CWE ID : CWE-
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-09-02
Technical Description
A vulnerability has been identified in Squid, which could be exploited by remote attackers to cause a denial of service. This flaw is due to an unspecified error in the "sslConnectTimeout()" function [src/ssl.c] that does not properly handle specially crafted requests, which could be exploited by attackers to crash Squid.