5
CVSSv2

CVE-2007-0248

Published: 16/01/2007 Updated: 29/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The aclMatchExternal function in Squid prior to 2.6.STABLE7 allows remote malicious users to cause a denial of service (crash) by causing an external_acl queue overload, which triggers an infinite loop.

Vulnerable Product Search on Vulmon Subscribe to Product

squid squid 2.6.stable6

Vendor Advisories

David Duncan Ross Palmer and Henrik Nordstrom discovered that squid incorrectly handled special characters in FTP URLs Remote users with access to squid could crash the server leading to a denial of service (CVE-2007-0247) ...
Debian Bug report logs - #407202 CVE-2007-0248: squid: Denial of Service Vulnerabilities Package: squid; Maintainer for squid is Luigi Gangitano <luigi@debianorg>; Source for squid is src:squid (PTS, buildd, popcon) Reported by: Alex de Oliveira Silva <enerv@hostsk> Date: Tue, 16 Jan 2007 21:03:13 UTC Severity: im ...