CVE-2007-0248
published 2007-01-16CVE-2007-0248: The aclMatchExternal function in Squid before 2.6.STABLE7 allows remote attackers to cause a denial of service (crash) by causing an external_acl queue…
PriorityP421medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
6.69%
93.2th percentile
The aclMatchExternal function in Squid before 2.6.STABLE7 allows remote attackers to cause a denial of service (crash) by causing an external_acl queue overload, which triggers an infinite loop.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | squid | < squid 2.6.5-4 (bookworm) | squid 2.6.5-4 (bookworm) |
| squid | squid | — | — |
| squid | squid | >= 0 < 2.6.5-4 | 2.6.5-4 |
| squid | squid | >= 0 < 2.6.5-4 | 2.6.5-4 |
| squid | squid | >= 0 < 2.6.5-4 | 2.6.5-4 |
| squid | squid | >= 0 < 2.6.5-4 | 2.6.5-4 |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerable function is `aclMatchExternal` in Squid; triggering an external_acl queue overload causes an infinite loop (CPU starvation/crash). Monitor for sustained CPU spikes in the Squid process coinciding with external ACL helper exhaustion. ↗
- →This vulnerability is only exploitable when external ACL helpers are configured and in use. Deployments without `external_acl_type` directives in squid.conf are not affected. ↗
- →The attack vector is remote: any user with access to the Squid proxy can trigger the condition by exhausting the external ACL helper queue. Restrict proxy access to trusted clients as a compensating control. ↗
- ·Only Squid versions before 2.6.STABLE7 are vulnerable. Squid 2.6.STABLE7 and later contain the fix. ↗
- ·Red Hat Enterprise Linux 2.1, 3, 4, and 5 are not affected — RHEL 5 carries a backported patch and earlier versions were never vulnerable. ↗
- ·Debian resolved this in package version 2.6.5-4 across all active suites (bookworm, bullseye, forky, sid, trixie). ↗
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Squid vulnerabilities
vendor_ubuntu·2007-01-25·CVSS 5.0
CVE-2007-0247 [MEDIUM] Squid vulnerabilities
Title: Squid vulnerabilities
Summary: Squid vulnerabilities
David Duncan Ross Palmer and Henrik Nordstrom discovered that squid
incorrectly handled special characters in FTP URLs. Remote users with
access to squid could crash the server leading to a denial of service.
(CVE-2007-0247)
Erick Dantas Rotole and Henrik Nordstrom discovered that squid could end
up in an endless loop when exhausted of available external ACL helpers.
Remote users with access to squid could cause CPU starvation, possibly
leading to a denial of service. This does not affect a default Ubuntu
installation, since external ACL helpers must be configured and used.
(CVE-2007-0248)
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2007-0248: squid - The aclMatchExternal function in Squid before 2.6.STABLE7 allows remote attacker...
vendor_debian·2007·CVSS 5.0
CVE-2007-0248 [MEDIUM] CVE-2007-0248: squid - The aclMatchExternal function in Squid before 2.6.STABLE7 allows remote attacker...
The aclMatchExternal function in Squid before 2.6.STABLE7 allows remote attackers to cause a denial of service (crash) by causing an external_acl queue overload, which triggers an infinite loop.
Scope: local
bookworm: resolved (fixed in 2.6.5-4)
bullseye: resolved (fixed in 2.6.5-4)
forky: resolved (fixed in 2.6.5-4)
sid: resolved (fixed in 2.6.5-4)
trixie: resolved (fixed in 2.6.5-4)
Red Hat
CVE-2007-0248: The aclMatchExternal function in Squid before 2
vendor_redhat·CVSS 5.0
CVE-2007-0248 [MEDIUM] CVE-2007-0248: The aclMatchExternal function in Squid before 2
The aclMatchExternal function in Squid before 2.6.STABLE7 allows remote attackers to cause a denial of service (crash) by causing an external_acl queue overload, which triggers an infinite loop.
Statement: Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
This issue did not affect the versions of Squid as shipped with Red Hat Enterprise Linux 2.1, 3, or 4.
GHSA
GHSA-w46f-hrch-xgr2: The aclMatchExternal function in Squid before 2
ghsa_unreviewed·2022-05-01
CVE-2007-0248 [MEDIUM] GHSA-w46f-hrch-xgr2: The aclMatchExternal function in Squid before 2
The aclMatchExternal function in Squid before 2.6.STABLE7 allows remote attackers to cause a denial of service (crash) by causing an external_acl queue overload, which triggers an infinite loop.
OSV
CVE-2007-0248: The aclMatchExternal function in Squid before 2
osv·2007-01-16·CVSS 5.0
CVE-2007-0248 [MEDIUM] CVE-2007-0248: The aclMatchExternal function in Squid before 2
The aclMatchExternal function in Squid before 2.6.STABLE7 allows remote attackers to cause a denial of service (crash) by causing an external_acl queue overload, which triggers an infinite loop.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/23767http://secunia.com/advisories/23805http://secunia.com/advisories/23889http://secunia.com/advisories/23921http://secunia.com/advisories/23946http://www.gentoo.org/security/en/glsa/glsa-200701-22.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:026http://www.novell.com/linux/security/advisories/2007_12_squid.htmlhttp://www.securityfocus.com/bid/22203http://www.squid-cache.org/Versions/v2/2.6/squid-2.6.STABLE7-RELEASENOTES.html#s12http://www.squid-cache.org/bugs/show_bug.cgi?id=1848http://www.ubuntu.com/usn/usn-414-1http://www.vupen.com/english/advisories/2007/0199https://exchange.xforce.ibmcloud.com/vulnerabilities/31525http://secunia.com/advisories/23767http://secunia.com/advisories/23805http://secunia.com/advisories/23889http://secunia.com/advisories/23921http://secunia.com/advisories/23946http://www.gentoo.org/security/en/glsa/glsa-200701-22.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:026http://www.novell.com/linux/security/advisories/2007_12_squid.htmlhttp://www.securityfocus.com/bid/22203http://www.squid-cache.org/Versions/v2/2.6/squid-2.6.STABLE7-RELEASENOTES.html#s12http://www.squid-cache.org/bugs/show_bug.cgi?id=1848http://www.ubuntu.com/usn/usn-414-1http://www.vupen.com/english/advisories/2007/0199https://exchange.xforce.ibmcloud.com/vulnerabilities/31525
2007-01-16
Published