Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-24606

Опубликовано: 24 авг. 2020
Источник: debian
EPSS Низкий

Описание

Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only occurs when cache_peer is used with the cache digests feature. The problem exists because peerDigestHandleReply() livelocking in peer_digest.cc mishandles EOF.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
squidfixed4.13-1package
squid3removedpackage

Примечания

  • https://github.com/squid-cache/squid/security/advisories/GHSA-vvj7-xjgq-g2jg

  • Squid 4: http://www.squid-cache.org/Versions/v4/changesets/SQUID-2020_9.patch

EPSS

Процентиль: 88%
0.0417
Низкий

Связанные уязвимости

CVSS3: 8.6
ubuntu
почти 5 лет назад

Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only occurs when cache_peer is used with the cache digests feature. The problem exists because peerDigestHandleReply() livelocking in peer_digest.cc mishandles EOF.

CVSS3: 7.5
redhat
почти 5 лет назад

Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only occurs when cache_peer is used with the cache digests feature. The problem exists because peerDigestHandleReply() livelocking in peer_digest.cc mishandles EOF.

CVSS3: 8.6
nvd
почти 5 лет назад

Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only occurs when cache_peer is used with the cache digests feature. The problem exists because peerDigestHandleReply() livelocking in peer_digest.cc mishandles EOF.

CVSS3: 7.5
fstec
почти 5 лет назад

Уязвимость функции peerDigestHandleReply() прокси-сервера Squid, связанная с недостатком механизма проверки вводимых данных, позволяющая нарушителю вызвать отказ в обслуживании

suse-cvrf
почти 5 лет назад

Security update for squid

EPSS

Процентиль: 88%
0.0417
Низкий