Bird_banner_small4
Squid Proxy HTCP Packet Processing Denial of Service
TSL ID FSC20100215-07
CVE ID(s) CVE-2010-0639
Severity Moderate
Description

A denial of service vulnerability has reported in Squid Proxy. The vulnerability is due to an error when processing specially crafted Hypertext Caching Protocol (HTCP) packets. Remote attackers can exploit this issue by sending malicious HTCP packets to the target server.

Successful exploitation could result in a denial of service condition.

The vendor has released patches and new versions to address this issue:

http://www.squid-cache.org/Download

Affected Products
  • Squid Project Squid 2.x prior to 2.7.STABLE8
  • Squid Project Squid 3.0 prior to 3.0.STABLE24
CVSS Score Base 7.8 (AV:N/AC:L/Au:N/C:N/I:N/A:C):
  • Access vector is NETWORK
  • Access complexity is LOW
  • Level of authentication required is NONE
  • Impact of this vulnerability on data confidentiality is NONE
  • Impact of this vulnerability on data integrity is NONE
  • Impact of this vulnerability on data availability is COMPLETE
Temporal 5.8 (E:U/RL:OF/RC:C):
  • The exploitability level of this vulnerability is UNPROVEN
  • The remediation level of this vulnerability is OFFICIAL FIX
  • The report confidence level of this vulnerability is CONFIRMED