CVE-2007-6239 describes a denial-of-service vulnerability affecting Squid 2.x before 2.6.STABLE17 and Squid 3.0. This flaw, located in the cache update reply processing, allows remote attackers to crash the proxy server through unspecified HTTP header manipulations leading to an Array memory leak. With a CVSS score of 5.0, it is considered a medium-severity vulnerability, requiring no authentication and having low attack complexity, but only impacting availability. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0_patch2CPE matchmatch criteria | cpe:2.3:a:squid:squid_web_proxy_cache:2.0_patch2:*:*:*:*:*:*:* | ||
2.1_patch2CPE matchmatch criteria | cpe:2.3:a:squid:squid_web_proxy_cache:2.1_patch2:*:*:*:*:*:*:* | ||
2.3.stable4CPE matchmatch criteria | cpe:2.3:a:squid:squid_web_proxy_cache:2.3.stable4:*:*:*:*:*:*:* | ||
2.3.stable5CPE matchmatch criteria | cpe:2.3:a:squid:squid_web_proxy_cache:2.3.stable5:*:*:*:*:*:*:* | ||
2.4_stable2CPE matchmatch criteria | cpe:2.3:a:squid:squid_web_proxy_cache:2.4_stable2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.