SquidClamav: Denial of service A vulnerability in SquidClamav may result in Denial of Service. squidclamav 2012-09-24 2012-09-24 428778 remote 6.8 6.8

SquidClamav is a HTTP anti-virus for Squid based on ClamAV and ICAP.

SquidClamav does not properly escape URLs before passing them to the system command call.

A remote attacker could send a specially crafted URL to SquidClamav, possibly resulting in a Denial of Service condition.

There is no known workaround at this time.

All SquidClamav users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-proxy/squidclamav-6.8"
CVE-2012-3501 SquidClamav News keytoaster ackle