Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-49288

Опубликовано: 04 дек. 2023
Источник: debian
EPSS Низкий

Описание

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Affected versions of squid are subject to a a Use-After-Free bug which can lead to a Denial of Service attack via collapsed forwarding. All versions of Squid from 3.5 up to and including 5.9 configured with "collapsed_forwarding on" are vulnerable. Configurations with "collapsed_forwarding off" or without a "collapsed_forwarding" directive are not vulnerable. This bug is fixed by Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should remove all collapsed_forwarding lines from their squid.conf.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
squidfixed6.1-1package
squidignoredbookwormpackage
squidignoredbullseyepackage
squid3removedpackage

Примечания

  • https://github.com/squid-cache/squid/security/advisories/GHSA-rj5h-46j6-q2g5

  • https://megamansec.github.io/Squid-Security-Audit/trace-uaf.html

  • https://github.com/squid-cache/squid/pull/1127 possibly removed the vulnerable code.

EPSS

Процентиль: 81%
0.01659
Низкий

Связанные уязвимости

CVSS3: 8.6
ubuntu
больше 1 года назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Affected versions of squid are subject to a a Use-After-Free bug which can lead to a Denial of Service attack via collapsed forwarding. All versions of Squid from 3.5 up to and including 5.9 configured with "collapsed_forwarding on" are vulnerable. Configurations with "collapsed_forwarding off" or without a "collapsed_forwarding" directive are not vulnerable. This bug is fixed by Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should remove all collapsed_forwarding lines from their squid.conf.

CVSS3: 7.5
redhat
больше 1 года назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Affected versions of squid are subject to a a Use-After-Free bug which can lead to a Denial of Service attack via collapsed forwarding. All versions of Squid from 3.5 up to and including 5.9 configured with "collapsed_forwarding on" are vulnerable. Configurations with "collapsed_forwarding off" or without a "collapsed_forwarding" directive are not vulnerable. This bug is fixed by Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should remove all collapsed_forwarding lines from their squid.conf.

CVSS3: 8.6
nvd
больше 1 года назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Affected versions of squid are subject to a a Use-After-Free bug which can lead to a Denial of Service attack via collapsed forwarding. All versions of Squid from 3.5 up to and including 5.9 configured with "collapsed_forwarding on" are vulnerable. Configurations with "collapsed_forwarding off" or without a "collapsed_forwarding" directive are not vulnerable. This bug is fixed by Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should remove all collapsed_forwarding lines from their squid.conf.

CVSS3: 7.5
fstec
больше 1 года назад

Уязвимость компонента Collapsed Forwarding Handler прокси-сервера Squid, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.6
redos
11 месяцев назад

Множественные уязвимости squid

EPSS

Процентиль: 81%
0.01659
Низкий