CVE-2008-1612
EPSS 13.1%
Description
The arrayShrink function (lib/Array.c) in Squid 2.6.STABLE17 allows attackers to cause a denial of service (process exit) via unknown vectors that cause an array to shrink to 0 entries, which triggers an assert error. NOTE: this issue is due to an incorrect fix for CVE-2007-6239.
How to fix CVE-2008-1612
To remediate CVE-2008-1612, upgrade the affected package to a fixed version below.
- Debian/squid—upgrade to 2.6.18-1 or later
Is CVE-2008-1612 being exploited?
Moderate — EPSS is 13.1%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 2.6.18-1