Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-46728

Опубликовано: 06 нояб. 2023
Источник: ubuntu
Приоритет: medium
CVSS3: 7.5

Описание

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of Service attack against Squid's Gopher gateway. The gopher protocol is always available and enabled in Squid prior to Squid 6.0.1. Responses triggering this bug are possible to be received from any gopher server, even those without malicious intent. Gopher support has been removed in Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should reject all gopher URL requests.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

6.1-2ubuntu1
esm-infra/focal

not-affected

4.10-1ubuntu1.8
focal

released

4.10-1ubuntu1.8
jammy

released

5.7-0ubuntu0.22.04.2
lunar

released

5.7-1ubuntu3.1
mantic

not-affected

6.1-2ubuntu1
trusty

ignored

end of standard support
upstream

released

6.1-1
xenial

ignored

end of standard support

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

DNE

esm-infra/bionic

released

3.5.27-1ubuntu1.14+esm1
esm-infra/focal

DNE

esm-infra/xenial

released

3.5.12-1ubuntu7.16+esm2
focal

DNE

jammy

DNE

lunar

DNE

mantic

DNE

trusty

ignored

end of standard support

Показывать по

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
почти 2 года назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of Service attack against Squid's Gopher gateway. The gopher protocol is always available and enabled in Squid prior to Squid 6.0.1. Responses triggering this bug are possible to be received from any gopher server, even those without malicious intent. Gopher support has been removed in Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should reject all gopher URL requests.

CVSS3: 7.5
nvd
больше 1 года назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of Service attack against Squid's Gopher gateway. The gopher protocol is always available and enabled in Squid prior to Squid 6.0.1. Responses triggering this bug are possible to be received from any gopher server, even those without malicious intent. Gopher support has been removed in Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should reject all gopher URL requests.

CVSS3: 7.5
debian
больше 1 года назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and ...

suse-cvrf
больше 1 года назад

Security update for squid

suse-cvrf
больше 1 года назад

Security update for squid

7.5 High

CVSS3

Уязвимость CVE-2023-46728