|
|
Log in / Subscribe / Register

squidclamav: denial of service

Package(s):squidclamav CVE #(s):CVE-2012-3501
Created:September 25, 2012 Updated:September 26, 2012
Description: From the CVE entry:

The squidclamav_check_preview_handler function in squidclamav.c in SquidClamav 5.x before 5.8 and 6.x before 6.7 passes an unescaped URL to a system command call, which allows remote attackers to cause a denial of service (daemon crash) via a URL with certain characters, as demonstrated using %0D or %0A.

Alerts:
Gentoo 201209-08 squidclamav 2012-09-24

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds