Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0128

Опубликовано: 09 мар. 2014
Источник: redhat
CVSS2: 4.3
EPSS Средний

Описание

Squid 3.1 before 3.3.12 and 3.4 before 3.4.4, when SSL-Bump is enabled, allows remote attackers to cause a denial of service (assertion failure) via a crafted range request, related to state management.

Отчет

This issue did not affect the versions of squid as shipped with Red Hat Enterprise Linux 5 as they did not include support for SSL-bump.

Меры по смягчению последствий

To work-around this issue, disable SSL-bump for clients affected by adding "ssl_bump none" rule(s) at the top of the ssl_bump configuration directives. Alternatively, disable the SSL-bump feature completely by removing the "ssl-bump" option from all http_port and/or https_port configuration directives.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5squidNot affected
Red Hat Enterprise Linux 7squidNot affected
Red Hat Enterprise Linux 6squidFixedRHSA-2014:059703.06.2014

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1074870squid: denial of service when using SSL-Bump

EPSS

Процентиль: 98%
0.54968
Средний

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

Squid 3.1 before 3.3.12 and 3.4 before 3.4.4, when SSL-Bump is enabled, allows remote attackers to cause a denial of service (assertion failure) via a crafted range request, related to state management.

nvd
больше 11 лет назад

Squid 3.1 before 3.3.12 and 3.4 before 3.4.4, when SSL-Bump is enabled, allows remote attackers to cause a denial of service (assertion failure) via a crafted range request, related to state management.

debian
больше 11 лет назад

Squid 3.1 before 3.3.12 and 3.4 before 3.4.4, when SSL-Bump is enabled ...

github
больше 3 лет назад

Squid 3.1 before 3.3.12 and 3.4 before 3.4.4, when SSL-Bump is enabled, allows remote attackers to cause a denial of service (assertion failure) via a crafted range request, related to state management.

oracle-oval
около 11 лет назад

ELSA-2014-0597: squid security update (MODERATE)

EPSS

Процентиль: 98%
0.54968
Средний

4.3 Medium

CVSS2