CVE-2010-0639: Null Pointer Dereference
The htcpHandleTstRequest function in htcp.c in Squid 2.x before 2.6.STABLE24 and 2.7 before 2.7.STABLE8, and htcp.cc in 3.0 before 3.0.STABLE24, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via crafted packets to the HTCP port.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0639?
CVE-2010-0639 is classified as a Medium severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2010-0639?
To address CVE-2010-0639, upgrade to Squid versions 2.6.STABLE24, 2.7.STABLE8, or 3.0.STABLE24, or later.
What impact does CVE-2010-0639 have on my system?
CVE-2010-0639 can lead to a denial of service condition, causing the Squid daemon to crash.
What versions are affected by CVE-2010-0639?
CVE-2010-0639 affects Squid versions before 2.6.STABLE24, 2.7.STABLE8, and 3.0.STABLE24.
Is CVE-2010-0639 exploitable remotely?
Yes, CVE-2010-0639 can be exploited by remote attackers sending crafted packets to the HTCP port.