Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-50269

Опубликовано: 14 дек. 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Squid is a caching proxy for the Web. Due to an Uncontrolled Recursion bug in versions 2.6 through 2.7.STABLE9, versions 3.1 through 5.9, and versions 6.0.1 through 6.5, Squid may be vulnerable to a Denial of Service attack against HTTP Request parsing. This problem allows a remote client to perform Denial of Service attack by sending a large X-Forwarded-For header when the follow_x_forwarded_for feature is configured. This bug is fixed by Squid version 6.6. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives.

A flaw was found in Squid, which is susceptible to a Denial of Service (DoS) due to an Uncontrolled Recursion bug, specifically targeting HTTP Request parsing. Exploiting this issue involves a remote client initiating a DoS attack by sending an oversized X-Forwarded-For header when the follow_x_forwarded_for feature is configured. This issue poses a threat to the stability and availability of the Squid service.

Отчет

Squid configurations lacking the "follow_x_forwarded_for" setting are not susceptible to the vulnerability.

Меры по смягчению последствий

Remove all "follow_x_forwarded_for" lines from squid.conf.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6squidOut of support scope
Red Hat Enterprise Linux 6squid34Out of support scope
Red Hat Enterprise Linux 7squidFixedRHSA-2024:178711.04.2024
Red Hat Enterprise Linux 8squidFixedRHSA-2024:137519.03.2024
Red Hat Enterprise Linux 8.2 Advanced Update SupportsquidFixedRHSA-2024:077212.02.2024
Red Hat Enterprise Linux 8.2 Telecommunications Update ServicesquidFixedRHSA-2024:077212.02.2024
Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionssquidFixedRHSA-2024:077212.02.2024
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportsquidFixedRHSA-2024:077312.02.2024
Red Hat Enterprise Linux 8.4 Telecommunications Update ServicesquidFixedRHSA-2024:077312.02.2024
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionssquidFixedRHSA-2024:077312.02.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-674
https://bugzilla.redhat.com/show_bug.cgi?id=2254663squid: denial of service in HTTP request parsing

EPSS

Процентиль: 80%
0.0149
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
ubuntu
больше 1 года назад

Squid is a caching proxy for the Web. Due to an Uncontrolled Recursion bug in versions 2.6 through 2.7.STABLE9, versions 3.1 through 5.9, and versions 6.0.1 through 6.5, Squid may be vulnerable to a Denial of Service attack against HTTP Request parsing. This problem allows a remote client to perform Denial of Service attack by sending a large X-Forwarded-For header when the follow_x_forwarded_for feature is configured. This bug is fixed by Squid version 6.6. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives.

CVSS3: 8.6
nvd
больше 1 года назад

Squid is a caching proxy for the Web. Due to an Uncontrolled Recursion bug in versions 2.6 through 2.7.STABLE9, versions 3.1 through 5.9, and versions 6.0.1 through 6.5, Squid may be vulnerable to a Denial of Service attack against HTTP Request parsing. This problem allows a remote client to perform Denial of Service attack by sending a large X-Forwarded-For header when the follow_x_forwarded_for feature is configured. This bug is fixed by Squid version 6.6. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives.

CVSS3: 8.6
debian
больше 1 года назад

Squid is a caching proxy for the Web. Due to an Uncontrolled Recursion ...

CVSS3: 8.6
fstec
больше 1 года назад

Уязвимость функции follow_x_forwarded_for() прокси-сервера Squid, позволяющая нарушителю вызвать отказ в обслуживании

suse-cvrf
больше 1 года назад

Security update for squid

EPSS

Процентиль: 80%
0.0149
Низкий

7.5 High

CVSS3