A vulnerability in SquidClamav may result in Denial of Service.
Package | net-proxy/squidclamav on all architectures |
---|---|
Affected versions | < 6.8 |
Unaffected versions | >= 6.8 |
SquidClamav is a HTTP anti-virus for Squid based on ClamAV and ICAP.
SquidClamav does not properly escape URLs before passing them to the system command call.
A remote attacker could send a specially crafted URL to SquidClamav, possibly resulting in a Denial of Service condition.
There is no known workaround at this time.
All SquidClamav users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=net-proxy/squidclamav-6.8"
Release date
September 24, 2012
Latest revision
September 24, 2012: 1
Severity
normal
Exploitable
remote
Bugzilla entries