Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-49288

Опубликовано: 04 дек. 2023
Источник: ubuntu
Приоритет: medium
CVSS3: 8.6

Описание

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Affected versions of squid are subject to a a Use-After-Free bug which can lead to a Denial of Service attack via collapsed forwarding. All versions of Squid from 3.5 up to and including 5.9 configured with "collapsed_forwarding on" are vulnerable. Configurations with "collapsed_forwarding off" or without a "collapsed_forwarding" directive are not vulnerable. This bug is fixed by Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should remove all collapsed_forwarding lines from their squid.conf.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

esm-infra/focal

not-affected

4.10-1ubuntu1.12
focal

released

4.10-1ubuntu1.12
jammy

released

5.7-0ubuntu0.22.04.4
lunar

ignored

end of life, was deferred [2024-01-26]
mantic

not-affected

6.1-2ubuntu1.1
noble

not-affected

oracular

not-affected

plucky

not-affected

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

DNE

esm-infra/bionic

needed

esm-infra/focal

DNE

esm-infra/xenial

needed

focal

DNE

jammy

DNE

lunar

DNE

mantic

DNE

noble

DNE

Показывать по

8.6 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
больше 1 года назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Affected versions of squid are subject to a a Use-After-Free bug which can lead to a Denial of Service attack via collapsed forwarding. All versions of Squid from 3.5 up to and including 5.9 configured with "collapsed_forwarding on" are vulnerable. Configurations with "collapsed_forwarding off" or without a "collapsed_forwarding" directive are not vulnerable. This bug is fixed by Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should remove all collapsed_forwarding lines from their squid.conf.

CVSS3: 8.6
nvd
больше 1 года назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Affected versions of squid are subject to a a Use-After-Free bug which can lead to a Denial of Service attack via collapsed forwarding. All versions of Squid from 3.5 up to and including 5.9 configured with "collapsed_forwarding on" are vulnerable. Configurations with "collapsed_forwarding off" or without a "collapsed_forwarding" directive are not vulnerable. This bug is fixed by Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should remove all collapsed_forwarding lines from their squid.conf.

CVSS3: 8.6
debian
больше 1 года назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and ...

CVSS3: 7.5
fstec
больше 1 года назад

Уязвимость компонента Collapsed Forwarding Handler прокси-сервера Squid, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.6
redos
11 месяцев назад

Множественные уязвимости squid

8.6 High

CVSS3

Уязвимость CVE-2023-49288