CVE-2010-0639Squid vulnerability

8 documents8 sources
Severity
5.0MEDIUMNVD
EPSS
49.4%
top 2.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 15
Latest updateMay 2

Description

The htcpHandleTstRequest function in htcp.c in Squid 2.x before 2.6.STABLE24 and 2.7 before 2.7.STABLE8, and htcp.cc in 3.0 before 3.0.STABLE24, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via crafted packets to the HTCP port.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debiansquid/squid< 2.7.STABLE8-1+3
NVDsquid-cache/squid31 versions+30

Patches

🔴Vulnerability Details

3
GHSA
GHSA-cg3x-2572-rpvr: The htcpHandleTstRequest function in htcp2022-05-02
OSV
CVE-2010-0639: The htcpHandleTstRequest function in htcp2010-02-15
CVEList
CVE-2010-0639: The htcpHandleTstRequest function in htcp2010-02-15

📋Vendor Advisories

3
Ubuntu
Squid vulnerability2010-02-24
Red Hat
squid: HTCP packet temporary DoS (SQUID-2010:2)2010-02-12
Debian
CVE-2010-0639: squid - The htcpHandleTstRequest function in htcp.c in Squid 2.x before 2.6.STABLE24 and...2010

💬Community

1
Bugzilla
CVE-2010-0639 squid: HTCP packet temporary DoS (SQUID-2010:2)2010-02-15
CVE-2010-0639 — Squid-cache Squid vulnerability | cvebase