First published: Tue Apr 01 2008(Updated: )
The arrayShrink function (lib/Array.c) in Squid 2.6.STABLE17 allows attackers to cause a denial of service (process exit) via unknown vectors that cause an array to shrink to 0 entries, which triggers an assert error. NOTE: this issue is due to an incorrect fix for CVE-2007-6239.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Squid Web Proxy Cache | =2.6.stable17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1612 is classified as a high-severity vulnerability that can lead to denial of service.
To fix CVE-2008-1612, upgrade to a version of Squid that is not affected, as the vulnerability exists specifically in Squid 2.6.STABLE17.
CVE-2008-1612 is a denial of service vulnerability affecting the arrayShrink function in Squid.
Yes, CVE-2008-1612 can potentially be exploited remotely, leading to a process exit.
CVE-2008-1612 was caused by an incorrect fix for a previous vulnerability, specifically CVE-2007-6239.