First published: Tue Jan 16 2007(Updated: )
The aclMatchExternal function in Squid before 2.6.STABLE7 allows remote attackers to cause a denial of service (crash) by causing an external_acl queue overload, which triggers an infinite loop.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Squid Web Proxy Cache | =2.6.stable6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0248 is classified as a high severity vulnerability due to its potential for causing a denial of service.
To rectify CVE-2007-0248, you should upgrade to Squid version 2.6.STABLE7 or later.
CVE-2007-0248 affects Squid version 2.6.STABLE6 and earlier.
CVE-2007-0248 allows remote attackers to crash the server, resulting in a denial of service.
There is no separate patch for CVE-2007-0248; the issue is resolved by upgrading to the compatible version.