Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-49288

Опубликовано: 04 дек. 2023
Источник: nvd
CVSS3: 8.6
CVSS3: 7.5
EPSS Низкий

Описание

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Affected versions of squid are subject to a a Use-After-Free bug which can lead to a Denial of Service attack via collapsed forwarding. All versions of Squid from 3.5 up to and including 5.9 configured with "collapsed_forwarding on" are vulnerable. Configurations with "collapsed_forwarding off" or without a "collapsed_forwarding" directive are not vulnerable. This bug is fixed by Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should remove all collapsed_forwarding lines from their squid.conf.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:*
Версия от 3.5 (включая) до 5.9 (включая)

EPSS

Процентиль: 81%
0.01659
Низкий

8.6 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 8.6
ubuntu
больше 1 года назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Affected versions of squid are subject to a a Use-After-Free bug which can lead to a Denial of Service attack via collapsed forwarding. All versions of Squid from 3.5 up to and including 5.9 configured with "collapsed_forwarding on" are vulnerable. Configurations with "collapsed_forwarding off" or without a "collapsed_forwarding" directive are not vulnerable. This bug is fixed by Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should remove all collapsed_forwarding lines from their squid.conf.

CVSS3: 7.5
redhat
больше 1 года назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Affected versions of squid are subject to a a Use-After-Free bug which can lead to a Denial of Service attack via collapsed forwarding. All versions of Squid from 3.5 up to and including 5.9 configured with "collapsed_forwarding on" are vulnerable. Configurations with "collapsed_forwarding off" or without a "collapsed_forwarding" directive are not vulnerable. This bug is fixed by Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should remove all collapsed_forwarding lines from their squid.conf.

CVSS3: 8.6
debian
больше 1 года назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and ...

CVSS3: 7.5
fstec
больше 1 года назад

Уязвимость компонента Collapsed Forwarding Handler прокси-сервера Squid, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.6
redos
11 месяцев назад

Множественные уязвимости squid

EPSS

Процентиль: 81%
0.01659
Низкий

8.6 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-416