Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The squidclamav_check_preview_handler function in squidclamav.c in SquidClamav 5.x before 5.8 and 6.x before 6.7 passes an unescaped URL to a system command call, which allows remote attackers to cause a denial of service (daemon crash) via a URL with certain characters, as demonstrated using %0D or %0A.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SquidClamav URL解析拒绝服务漏洞
Vulnerability Description
SquidClamav 5.8之前的5.x版本和6.7之前的6.x版本中的squidclamav.c内的squidclamav_check_preview_handler函数中存在拒绝服务漏洞。攻击者可利用该漏洞导致守护进程崩溃,拒绝为合法用户提供服务。
CVSS Information
N/A
Vulnerability Type
N/A