CVE-2010-0639
Publication date 15 February 2010
Last updated 24 July 2024
Ubuntu priority
The htcpHandleTstRequest function in htcp.c in Squid 2.x before 2.6.STABLE24 and 2.7 before 2.7.STABLE8, and htcp.cc in 3.0 before 3.0.STABLE24, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via crafted packets to the HTCP port.
Status
Package | Ubuntu Release | Status |
---|---|---|
squid | ||
squid3 | ||
Notes
mdeslaur
code not present in dapper (It's actually the htcpHandleClr function that is being patched here)
Patch details
Package | Patch details |
---|---|
squid | |
squid3 |
References
Related Ubuntu Security Notices (USN)
- USN-904-1
- Squid vulnerability
- 24 February 2010