Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-46847

Опубликовано: 03 нояб. 2023
Источник: debian
EPSS Средний

Описание

Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
squidfixed6.5-1package
squid3removedpackage

Примечания

  • https://github.com/squid-cache/squid/security/advisories/GHSA-phqj-m8gv-cq4g

  • https://github.com/squid-cache/squid/commit/052cf082b0faaef4eaaa4e94119d7a1437aac4a3

  • https://megamansec.github.io/Squid-Security-Audit/digest-overflow.html

EPSS

Процентиль: 98%
0.50113
Средний

Связанные уязвимости

CVSS3: 8.6
ubuntu
больше 1 года назад

Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.

CVSS3: 8.6
redhat
больше 1 года назад

Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.

CVSS3: 8.6
nvd
больше 1 года назад

Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.

oracle-oval
больше 1 года назад

ELSA-2023-6884: squid security update (CRITICAL)

oracle-oval
больше 1 года назад

ELSA-2023-6882: squid34 security update (CRITICAL)

EPSS

Процентиль: 98%
0.50113
Средний