|
|
|
![]() |
Vulnerability Note VU#823350Squid fails to properly handle oversized reply headersOverviewThe Squid web proxy cache may be vulnerable to oversized HTTP reply headers.I. DescriptionSquid functions as a web proxy and cache application for a number of protocols, including the hypertext transfer protocol (HTTP). A defect in the Squid HTTP handling prevents oversized reply headers relating to an HTTP protocol mismatch from being handled properly.II. ImpactThe complete impact of this vulnerability is not yet known. This vulnerability is platform independent.III. SolutionApply an updateAdministrators should obtain an updated version of Squid from their vendor.
References
Thanks to Team Squid for reporting this vulnerability, who in turn credit Marc Elsen for finding the flaw. This document was written by Ken MacInnis based primarily on information provided by Team Squid.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||