CVE-2014-3609
squid - security update
EPSS 56.2%
描述
HttpHdrRange.cc in Squid 3.x before 3.3.12 and 3.4.x before 3.4.6 allows remote attackers to cause a denial of service (crash) via a request with crafted "Range headers with unidentifiable byte-range values."
如何修補 CVE-2014-3609
要修補 CVE-2014-3609,請將受影響套件升級到下列已修補版本。
- Debian/squid—升級至 2.7.STABLE9-5 或更新版本
- Debian/squid—升級至 2.7.STABLE9-2.1+deb6u1 或更新版本
- Debian/squid—升級至 2.7.STABLE9-4.1+deb7u1 或更新版本
- Debian/squid3—升級至 3.1.6-1.2+squeeze4 或更新版本
- —升級至 3.1.20-2.2+deb7u2 或更新版本
CVE-2014-3609 正在被利用嗎?
可能 — EPSS 為 56.2%,屬於高被利用機率區間,建議優先修補。
受影響套件(5)
- from 0, < 2.7.STABLE9-5
- from 0, < 2.7.STABLE9-2.1+deb6u1
- from 0, < 2.7.STABLE9-4.1+deb7u1
- from 0, < 3.1.6-1.2+squeeze4
- from 0, < 3.1.20-2.2+deb7u2