Summary
The remote host is missing an update to squid
announced via advisory USN-724-1.
Joshua Morin, Mikko Varpiola and Jukka Taimisto discovered that Squid did not properly validate the HTTP version when processing requests. A remote attacker could exploit this to cause a denial of service (assertion failure).
Solution
The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 8.10:
squid 2.7.STABLE3-1ubuntu2.1
In general, a standard system upgrade is sufficient to effect the necessary changes.
https://secure1.securityspace.com/smysecure/catid.html?in=USN-724-1
Severity
Classification
-
CVE CVE-2009-0478 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities