Note:
This project will be discontinued after December 13, 2021. [more]
2018-02-09
The Squid Software Foundation Squid HTTP Caching Proxy version prior to version 4.0.23 contains a NULL Pointer Dereference vulnerability in HTTP Response X-Forwarded-For header processing that can result in Denial of Service to all clients of the proxy. This attack appear to be exploitable via Remote HTTP server responding with an X-Forwarded-For header to certain types of HTTP request. This vulnerability appears to have been fixed in 4.0.23 and later.
Products | Ubuntu_linux, Debian_linux, Squid |
Type | NULL Pointer Dereference (CWE-476) |
First patch | - None (likely due to unavailable code) |
Links |
• http://www.squid-cache.org/Versions/v3/3.5/changesets/SQUID-2018_2.patch
• https://www.debian.org/security/2018/dsa-4122 • http://www.squid-cache.org/Versions/v4/changesets/SQUID-2018_2.patch • https://github.com/squid-cache/squid/pull/129/files • https://usn.ubuntu.com/4059-2/ |