Squid Proxy Server HTTP Vary Header Denial of Service

Strike ID:
E13-snb01
CVSS:
7.8 (AV:N/AC:L/Au:N/C:N/I:N/A:C)
False Positive:
f
Variants:
3
Year:
2013

Description

This strike exploits a denial of service vulnerability in Squid Proxy Server. A specially crafted Vary header can be used to cause Squid Proxy Server to terminate abnormally, terminating any current sessions. It will be restarted by Squid Monitor. Repeated attacks will cause Squid Monitor to exit without restarting Squid Proxy Server, causing a denial of service condition.

References