Squid: Denial of Service Squid is affected by a Denial of Service vulnerability. squid March 31, 2007 March 31, 2007: 01 171681 remote 2.6.12 2.6.12

Squid is a multi-protocol proxy server.

Squid incorrectly handles TRACE requests that contain a "Max-Forwards" header field with value "0" in the clientProcessRequest() function.

A remote attacker can send specially crafted TRACE HTTP requests that will terminate the child process. A quickly repeated attack will lead to a Denial of Service.

There is no known workaround at this time.

All Squid users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-proxy/squid-2.6.12"
CVE-2007-1560 aetius falco falco