4.3
CVSSv2

CVE-2008-1612

Published: 01/04/2008 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The arrayShrink function (lib/Array.c) in Squid 2.6.STABLE17 allows malicious users to cause a denial of service (process exit) via unknown vectors that cause an array to shrink to 0 entries, which triggers an assert error. NOTE: this issue is due to an incorrect fix for CVE-2007-6239.

Vulnerable Product Search on Vulmon Subscribe to Product

squid squid 2.6.stable17

Vendor Advisories

It was discovered that Squid did not perform proper bounds checking when processing cache update replies A remote authenticated user may be able to trigger an assertion error and cause a denial of service This vulnerability is due to an incorrect upstream fix for CVE-2007-6239 (CVE-2008-1612) ...
A weakness has been discovered in squid, a caching proxy server The flaw was introduced upstream in response to CVE-2007-6239, and announced by Debian in DSA-1482-1 The flaw involves an over-aggressive bounds check on an array resize, and could be exploited by an authorized client to induce a denial of service condition against squid For the sta ...