Intrusion Prevention

Squid.SSL.Bump.DoS

Description

This indicates an attempt to exploit a Denial of Service vulnerability in Squid.
The vulnerability is due to input validation when the vulnerable software handles a malformed TLS request. A remote attacker may be able to exploit this to cause a denial of service condition on the affected system, via crafted TLS packets.

Affected Products

Squid Project Squid Prior to 3.5.9

Impact

Denial of Service: Remote attackers can crash vulnerable systems.

Recommended Actions

Apply the most recent upgrade or patch from the vendor.
http://www.squid-cache.org/Advisories/SQUID-2015_3.txt

Other References

1033631