Squid HTTP Header Port Number Handling Denial of Service Vulnerability
Last Update Date:
16 Jul 2013 10:50
Release Date:
16 Jul 2013
4580
Views
RISK: Medium Risk
TYPE: Servers - Other Servers
A vulnerability has been identified in Squid, which can be exploited by malicious people to cause a DoS (Denial of Service).
The vulnerability is caused due to an error when handling port number values within the "Host" header of HTTP requests and can be exploited to render the service unusable.
Impact
- Denial of Service
System / Technologies affected
- Squid versions 3.2 through 3.2.12 and versions 3.3 through 3.3.7.
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 3.2.13 or 3.3.8 or apply patch.
Vulnerability Identifier
Source
Related Link
Share with