5
CVSSv2

CVE-2010-0639

Published: 15/02/2010 Updated: 02/08/2010
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The htcpHandleTstRequest function in htcp.c in Squid 2.x prior to 2.6.STABLE24 and 2.7 prior to 2.7.STABLE8, and htcp.cc in 3.0 prior to 3.0.STABLE24, allows remote malicious users to cause a denial of service (NULL pointer dereference and daemon crash) via crafted packets to the HTCP port.

Vulnerable Product Search on Vulmon Subscribe to Product

squid-cache squid 2.6

squid-cache squid 2.7

squid-cache squid 2.1

squid-cache squid 3.0.stable2

squid-cache squid 3.0.stable20

squid-cache squid 3.0.stable21

squid-cache squid 3.0.stable22

squid-cache squid 3.0.stable11

squid-cache squid 3.0.stable12

squid-cache squid 3.0.stable13

squid-cache squid 3.0.stable14

squid-cache squid 3.0.stable15

squid-cache squid 3.0.stable7

squid-cache squid 3.0.stable8

squid-cache squid 3.0.stable9

squid-cache squid 3.0.stable23

squid-cache squid 2.0

squid-cache squid 2.5

squid-cache squid 2.2

squid-cache squid 3.0

squid-cache squid 3.0.stable16

squid-cache squid 3.0.stable18

squid-cache squid 3.0.stable4

squid-cache squid 3.0.stable6

squid-cache squid 2.4

squid-cache squid 2.3

squid-cache squid 3.0.stable1

squid-cache squid 3.0.stable17

squid-cache squid 3.0.stable19

squid-cache squid 3.0.stable3

squid-cache squid 3.0.stable5

Vendor Advisories

Debian Bug report logs - #572553 CVE-2010-0639: HTCP DoS Package: squid; Maintainer for squid is Luigi Gangitano <luigi@debianorg>; Source for squid is src:squid (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Thu, 4 Mar 2010 20:51:09 UTC Severity: important Tags: security Found in ve ...
It was discovered that Squid incorrectly handled certain malformed packets received on the HTCP port A remote attacker could exploit this with a specially-crafted packet and cause Squid to crash, resulting in a denial of service ...