Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-33427

Опубликовано: 29 мар. 2024
Источник: redhat
CVSS3: 0

Описание

A flaw was found in Squid. A buffer over-read in the ConfigParser::UnQuote function in the src/ConfigParser.cc file can be triggered when a specially crafted configuration file is being parsed by Squid when it's initializing, causing an application crash.

Отчет

This CVE has been rejected and Red Hat Product Security does not consider this to be a vulnerability because this issue can only be triggered when Squid is initializing and by using a specially crafted configuration file. The only impact of this issue is an application crash before Squid is in fact started and running.

Меры по смягчению последствий

Do not use untrusted Squid configuration files.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10squidWill not fix
Red Hat Enterprise Linux 6squidOut of support scope
Red Hat Enterprise Linux 6squid34Out of support scope
Red Hat Enterprise Linux 7squidWill not fix
Red Hat Enterprise Linux 8squid:4/squidWill not fix
Red Hat Enterprise Linux 9squidWill not fix

Показывать по

Дополнительная информация

Дефект:
CWE-126
https://bugzilla.redhat.com/show_bug.cgi?id=2283380squid: buffer overread leading to denial of service

0 Low

CVSS3

Связанные уязвимости

nvd
больше 1 года назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

suse-cvrf
больше 1 года назад

Security update for squid

suse-cvrf
больше 1 года назад

Security update for squid

suse-cvrf
больше 1 года назад

Security update for squid

suse-cvrf
4 месяца назад

Security update for squid

0 Low

CVSS3