Squid sslConnectTimeout Function Remote DoS
High Log Correlation Engine Plugin ID 801036
SynopsisThe remote host is vulnerable to a Denial of Service (DoS) attack.
DescriptionThe remote Squid caching proxy, according to its version number, is vulnerable to an attack where the attacker can cause the Squid proxy to stop servicing valid service requests. The flaw is within the 'sslConnectTimeout' function and stems from the functions inability to parse user-supplied requests. Successful exploitation leads to a loss of availability.
SolutionUpgrade to version 2.5.STABLE11 (when available) or higher.