cbcvebase.
CVE-2008-1612
published 2008-04-01

CVE-2008-1612: The arrayShrink function (lib/Array.c) in Squid 2.6.STABLE17 allows attackers to cause a denial of service (process exit) via unknown vectors that cause an…

PriorityP411medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
2.18%
80.5th percentile
The arrayShrink function (lib/Array.c) in Squid 2.6.STABLE17 allows attackers to cause a denial of service (process exit) via unknown vectors that cause an array to shrink to 0 entries, which triggers an assert error. NOTE: this issue is due to an incorrect fix for CVE-2007-6239.

Affected

6 ranges
VendorProductVersion rangeFixed in
debiansquid< squid 2.6.18-1 (bookworm)squid 2.6.18-1 (bookworm)
squidsquid
squidsquid>= 0 < 2.6.18-12.6.18-1
squidsquid>= 0 < 2.6.18-12.6.18-1
squidsquid>= 0 < 2.6.18-12.6.18-1
squidsquid>= 0 < 2.6.18-12.6.18-1

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.