5

CVE-2007-6239

Exploit

The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial of service (crash) via unknown vectors related to HTTP headers and an Array memory leak during requests for cached objects.

Data is provided by the National Vulnerability Database (NVD)
SquidSquid Web Proxy Cache Version2.0_patch2
SquidSquid Web Proxy Cache Version2.1_patch2
SquidSquid Web Proxy Cache Version2.3.stable4
SquidSquid Web Proxy Cache Version2.3.stable5
SquidSquid Web Proxy Cache Version2.4_stable2
SquidSquid Web Proxy Cache Version2.4_stable4
SquidSquid Web Proxy Cache Version2.4_stable6
SquidSquid Web Proxy Cache Version2.4_stable7
SquidSquid Web Proxy Cache Version2.5.stable11
SquidSquid Web Proxy Cache Version2.5.stable12
SquidSquid Web Proxy Cache Version2.5.stable13
SquidSquid Web Proxy Cache Version2.5.stable14
SquidSquid Web Proxy Cache Version2.5_.stable9
SquidSquid Web Proxy Cache Version2.5_stable1
SquidSquid Web Proxy Cache Version2.5_stable3
SquidSquid Web Proxy Cache Version2.5_stable4
SquidSquid Web Proxy Cache Version2.5_stable5
SquidSquid Web Proxy Cache Version2.5_stable6
SquidSquid Web Proxy Cache Version2.5_stable7
SquidSquid Web Proxy Cache Version2.5_stable8
SquidSquid Web Proxy Cache Version2.5_stable10
SquidSquid Web Proxy Cache Version2.6
SquidSquid Web Proxy Cache Version2.6.stable1
SquidSquid Web Proxy Cache Version2.6.stable2
SquidSquid Web Proxy Cache Version2.6.stable3
SquidSquid Web Proxy Cache Version2.6.stable4
SquidSquid Web Proxy Cache Version2.6.stable5
SquidSquid Web Proxy Cache Version2.6.stable6
SquidSquid Web Proxy Cache Version2.6.stable7
SquidSquid Web Proxy Cache Version2.6.stable12
SquidSquid Web Proxy Cache Version2.6.stable13
SquidSquid Web Proxy Cache Version2.6.stable14
SquidSquid Web Proxy Cache Version2.6.stable15
SquidSquid Web Proxy Cache Version2.6.stable16
SquidSquid Web Proxy Cache Version3.0
SquidSquid Web Proxy Cache Version3.0_pre1
SquidSquid Web Proxy Cache Version3.0_pre2
SquidSquid Web Proxy Cache Version3.0_pre3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 14.35% 0.938
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.