Oval Definition:oval:com.ubuntu.trusty:def:20181172000
Revision Date:2018-05-16Version:1
Title:CVE-2018-1172 on Ubuntu 14.04 LTS (trusty) - low.
Description:This vulnerability allows remote attackers to deny service on vulnerable installations of The Squid Software Foundation Squid 3.5.27-20180318. Authentication is not required to exploit this vulnerability. The specific flaw exists within ClientRequestContext::sslBumpAccessCheck(). A crafted request can trigger the dereference of a null pointer. An attacker can leverage this vulnerability to create a denial-of-service condition to users of the system. Was ZDI-CAN-6088.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2018-1172
Platform(s):Ubuntu 14.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 14.04 LTS (trusty) is installed.
  • AND NOT While related to the CVE in some way, the 'squid3' package in trusty is not affected (note: 'not built with --with-openssl').
  • BACK