CVE-2007-1560

9 documents8 sources
Severity
5.0MEDIUM
EPSS
67.3%
top 1.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 21
Latest updateMay 1

Description

The clientProcessRequest() function in src/client_side.c in Squid 2.6 before 2.6.STABLE12 allows remote attackers to cause a denial of service (daemon crash) via crafted TRACE requests that trigger an assertion error.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debiansquid< 2.6.5-6+3
NVDsquid/squid11 versions+10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-cmwg-5hv4-pp63: The clientProcessRequest() function in src/client_side2022-05-01
CVEList
CVE-2007-1560: The clientProcessRequest() function in src/client_side2007-03-21
OSV
CVE-2007-1560: The clientProcessRequest() function in src/client_side2007-03-21

📋Vendor Advisories

3
Ubuntu
Squid vulnerability2007-03-26
Red Hat
security flaw2007-03-20
Debian
CVE-2007-1560: squid - The clientProcessRequest() function in src/client_side.c in Squid 2.6 before 2.6...2007

💬Community

2
Bugzilla
CVE-2007-1560 security flaw2018-08-16
Bugzilla
CVE-2007-1560 Squid TRACE DoS2007-03-21