A vulnerability in SquidClamav may result in Denial of Service.
|Package||net-proxy/squidclamav on all architectures|
|Affected versions||< 6.8|
|Unaffected versions||>= 6.8|
SquidClamav is a HTTP anti-virus for Squid based on ClamAV and ICAP.
SquidClamav does not properly escape URLs before passing them to the system command call.
A remote attacker could send a specially crafted URL to SquidClamav, possibly resulting in a Denial of Service condition.
There is no known workaround at this time.
All SquidClamav users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=net-proxy/squidclamav-6.8"
September 24, 2012
September 24, 2012: 1