Squid Proxy 2.5/2.6 - FTP URI Remote Denial of Service



EKU-ID: 34633 CVE: CVE-2007-0247;OSVDB-39839 OSVDB-ID:
Author: David Duncan Ross Palmer Published: 2007-01-16 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/22079/info

Squid is prone to a remote denial-of-service vulnerability because the proxy server fails to handle certain FTP requests.

Successfully exploiting this issue allows remote attackers to crash affected proxy applications, denying futher service to legitimate users.

Squid versions from 2.5.STABLE11 to 2.6.STABLE6 are vulnerable to this issue.

ftp://www.example.com/sample/directory;type=d