Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-49285

Опубликовано: 04 дек. 2023
Источник: redhat
CVSS3: 7.5

Описание

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

A buffer over-read flaw was found in Squid's HTTP Message processing feature. This issue may allow attackers to perform remote denial of service.

Отчет

The only security impact of this vulnerability is a remote denial of service. For this reason, this flaw was rated with an important, and not critical, severity.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6squidOut of support scope
Red Hat Enterprise Linux 6squid34Out of support scope
Red Hat Enterprise Linux 7squidFixedRHSA-2024:178711.04.2024
Red Hat Enterprise Linux 8squidFixedRHSA-2024:004603.01.2024
Red Hat Enterprise Linux 8.2 Advanced Update SupportsquidFixedRHSA-2024:077212.02.2024
Red Hat Enterprise Linux 8.2 Telecommunications Update ServicesquidFixedRHSA-2024:077212.02.2024
Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionssquidFixedRHSA-2024:077212.02.2024
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportsquidFixedRHSA-2024:077312.02.2024
Red Hat Enterprise Linux 8.4 Telecommunications Update ServicesquidFixedRHSA-2024:077312.02.2024
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionssquidFixedRHSA-2024:077312.02.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-126
https://bugzilla.redhat.com/show_bug.cgi?id=2252926squid: Buffer over-read in the HTTP Message processing feature

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
ubuntu
больше 1 года назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 8.6
nvd
больше 1 года назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 8.6
debian
больше 1 года назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and ...

CVSS3: 8.6
fstec
больше 1 года назад

Уязвимость прокси-сервера Squid, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании

suse-cvrf
больше 1 года назад

Security update for squid

7.5 High

CVSS3