CVE-2007-6239

UnknownEPSS 26.86%

Last modified

CVE-2007-6239 is a vulnerability of currently unknown severity. The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial of service (crash) via unknown vectors related to HTTP headers and an Array memory leak during requests for cached objects.. EPSS estimates a 26.86% chance of exploitation in the next 30 days.

Description

The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial of service (crash) via unknown vectors related to HTTP headers and an Array memory leak during requests for cached objects.

Metrics

EPSS Probability
26.86%

97.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
SquidSquid Web Proxy Cache2.0_patch2
SquidSquid Web Proxy Cache2.1_patch2
SquidSquid Web Proxy Cache2.3.stable4
SquidSquid Web Proxy Cache2.3.stable5
SquidSquid Web Proxy Cache2.4_stable2
SquidSquid Web Proxy Cache2.4_stable4
SquidSquid Web Proxy Cache2.4_stable6
SquidSquid Web Proxy Cache2.4_stable7
SquidSquid Web Proxy Cache2.5.stable11
SquidSquid Web Proxy Cache2.5.stable12
SquidSquid Web Proxy Cache2.5.stable13
SquidSquid Web Proxy Cache2.5.stable14
SquidSquid Web Proxy Cache2.5_.stable9
SquidSquid Web Proxy Cache2.5_stable1
SquidSquid Web Proxy Cache2.5_stable3
SquidSquid Web Proxy Cache2.5_stable4
SquidSquid Web Proxy Cache2.5_stable5
SquidSquid Web Proxy Cache2.5_stable6
SquidSquid Web Proxy Cache2.5_stable7
SquidSquid Web Proxy Cache2.5_stable8
SquidSquid Web Proxy Cache2.5_stable10
SquidSquid Web Proxy Cache2.6
SquidSquid Web Proxy Cache2.6.stable1
SquidSquid Web Proxy Cache2.6.stable2
SquidSquid Web Proxy Cache2.6.stable3
SquidSquid Web Proxy Cache2.6.stable4
SquidSquid Web Proxy Cache2.6.stable5
SquidSquid Web Proxy Cache2.6.stable6
SquidSquid Web Proxy Cache2.6.stable7
SquidSquid Web Proxy Cache2.6.stable12
SquidSquid Web Proxy Cache2.6.stable13
SquidSquid Web Proxy Cache2.6.stable14
SquidSquid Web Proxy Cache2.6.stable15
SquidSquid Web Proxy Cache2.6.stable16
SquidSquid Web Proxy Cache3.0
SquidSquid Web Proxy Cache3.0_pre1
SquidSquid Web Proxy Cache3.0_pre2
SquidSquid Web Proxy Cache3.0_pre3

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2007-6239?
The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial of service (crash) via unknown vectors related to HTTP headers and an Array memory leak during requests for cached objects.
How severe is CVE-2007-6239?
Severity scoring for CVE-2007-6239 is pending analysis. The EPSS model estimates a 26.86% probability of exploitation in the next 30 days.
How do I fix CVE-2007-6239?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2007-6239?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST