MEDIUM
squid: regression in SQUID-2007:2 / CVE-2007-6239
Published Apr 1, 2008
4.3
MEDIUMCVSS 2.0
EPSS 2.18%
Description
The arrayShrink function (lib/Array.c) in Squid 2.6.STABLE17 allows attackers to cause a denial of service (process exit) via unknown vectors that cause an array to shrink to 0 entries, which triggers an assert error. NOTE: this issue is due to an incorrect fix for CVE-2007-6239.
Affected products
No data.
No data.
Red Hat Enterprise Linux 2.1
squid-7:2.4.STABLE7-1.21as.12
Fixed · RHSA-2008:0214
Red Hat Enterprise Linux 3
squid-7:2.5.STABLE3-9.3E
Fixed · RHSA-2008:0214
Red Hat Enterprise Linux 4
squid-7:2.5.STABLE14-1.4E.el4_6.2
Fixed · RHSA-2008:0214
Red Hat Enterprise Linux 5
squid-7:2.6.STABLE6-5.el5_1.3
Fixed · RHSA-2008:0214
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 2.1 | squid-7:2.4.STABLE7-1.21as.12 | Fixed | RHSA-2008:0214 |
| Red Hat Enterprise Linux 3 | squid-7:2.5.STABLE3-9.3E | Fixed | RHSA-2008:0214 |
| Red Hat Enterprise Linux 4 | squid-7:2.5.STABLE14-1.4E.el4_6.2 | Fixed | RHSA-2008:0214 |
| Red Hat Enterprise Linux 5 | squid-7:2.6.STABLE6-5.el5_1.3 | Fixed | RHSA-2008:0214 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (23)
- http://lists.opensuse.org/opensuse-security-announce/2008-05/msg00000.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=squid-announce&m=120614453813157&w=2 mailing-listx_refsource_MLIST
- http://secunia.com/advisories/27477 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29813 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30032 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/32109 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/34467 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-200903-38.xml vendor-advisoryx_refsource_GENTOO
- http://www.debian.org/security/2008/dsa-1646 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:134 vendor-advisoryx_refsource_MANDRIVA
- http://www.openwall.com/lists/oss-security/2008/04/01/5 mailing-listx_refsource_MLIST
- http://www.redhat.com/support/errata/RHSA-2008-0214.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/28693 vdb-entryx_refsource_BID
- http://www.squid-cache.org/Advisories/SQUID-2007_2.txt x_refsource_CONFIRMPatch
- http://www.squid-cache.org/Versions/v2/2.6/changesets/11882.patch x_refsource_MISCExploit
- http://www.ubuntu.com/usn/usn-601-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2008-1612 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=439801 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41586 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2008-1612
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11376 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2008-1612
- https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00560.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 1, 2008
Updated Aug 7, 2024
Reserved Apr 1, 2008
Link CVE-2008-1612
CISA Vulnrichment
Updated n/a