CVE-2012-3501: Darold Squidclamav
Medium severity, CVSS 5.0. EPSS: 3.3% chance of exploitation in the next 30 days.
The squidclamav_check_preview_handler function in squidclamav.c in SquidClamav 5.x before 5.8 and 6.x before 6.7 passes an unescaped URL to a system command call, which allows remote attackers to cause a denial of service (daemon crash) via a URL with certain characters, as demonstrated using %0D or %0A.
Affected products
- Darold Squidclamav: version 5.0 only; version 5.1 only; version 5.2 only; version 5.3 only; version 5.4 only; version 5.5 only; …
Published 2012-08-25. Last modified 2026-06-16.