>> Squid "clientProcessRequest()" TRACE Request Handling Denial of Service Vulnerability
Title : Squid "clientProcessRequest()" TRACE Request Handling Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2007-1035 CVE ID : CVE-2007-1560
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-03-21
Technical Description
A vulnerability has been identified in Squid, which could be exploited by attackers to cause a denial of service. This issue is due to an error in the "clientProcessRequest()" [squid/src/client_side.c] function when processing certain "TRACE" requests, which could be exploited by an authorized client to create a denial of service condition by sending a specially crafted request to an affected proxy.