>> Squid Cache Update Reply Processing Denial of Service Vulnerability
Title : Squid Cache Update Reply Processing Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2007-4066 CVE ID : CVE-2007-6239 - CVE-2008-1612
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-12-04
Technical Description
A vulnerability has been identified in Squid, which could be exploited by attackers to cause a denial of service. This issue is caused due to incorrect bounds checking within the "httpHeaderUpdate()" [HttpHeader.c] function when processing cache update replies, which could be exploited by malicious clients to crash an affected server, creating a denial of service condition.