Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-49288

Опубликовано: 05 дек. 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Affected versions of squid are subject to a a Use-After-Free bug which can lead to a Denial of Service attack via collapsed forwarding. All versions of Squid from 3.5 up to and including 5.9 configured with "collapsed_forwarding on" are vulnerable. Configurations with "collapsed_forwarding off" or without a "collapsed_forwarding" directive are not vulnerable. This bug is fixed by Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should remove all collapsed_forwarding lines from their squid.conf.

A flaw was found in Squid. The use of the HTTP Collapsed Forwarding configuration may allow an attacker to perform a denial of service remotely.

Отчет

Collapsed Forwarding features are only used in Squid for accelerator servers and is not enabled by default, lowering the severity of this flaw to Moderate.

Меры по смягчению последствий

To mitigate this issue, lines for the 'collapsed_forwarding' feature have to be removed from your squid.conf.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6squidOut of support scope
Red Hat Enterprise Linux 6squid34Out of support scope
Red Hat Enterprise Linux 7squidOut of support scope
Red Hat Enterprise Linux 8squidFixedRHSA-2023:766806.12.2023
Red Hat Enterprise Linux 9squidFixedRHSA-2023:746522.11.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2252918squid: Use-After-Free in the HTTP Collapsed Forwarding Feature

EPSS

Процентиль: 81%
0.01659
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
ubuntu
больше 1 года назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Affected versions of squid are subject to a a Use-After-Free bug which can lead to a Denial of Service attack via collapsed forwarding. All versions of Squid from 3.5 up to and including 5.9 configured with "collapsed_forwarding on" are vulnerable. Configurations with "collapsed_forwarding off" or without a "collapsed_forwarding" directive are not vulnerable. This bug is fixed by Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should remove all collapsed_forwarding lines from their squid.conf.

CVSS3: 8.6
nvd
больше 1 года назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Affected versions of squid are subject to a a Use-After-Free bug which can lead to a Denial of Service attack via collapsed forwarding. All versions of Squid from 3.5 up to and including 5.9 configured with "collapsed_forwarding on" are vulnerable. Configurations with "collapsed_forwarding off" or without a "collapsed_forwarding" directive are not vulnerable. This bug is fixed by Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should remove all collapsed_forwarding lines from their squid.conf.

CVSS3: 8.6
debian
больше 1 года назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and ...

CVSS3: 7.5
fstec
больше 1 года назад

Уязвимость компонента Collapsed Forwarding Handler прокси-сервера Squid, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.6
redos
11 месяцев назад

Множественные уязвимости squid

EPSS

Процентиль: 81%
0.01659
Низкий

7.5 High

CVSS3