Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-5824

Опубликовано: 03 нояб. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.5

Описание

A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the worker process when a large header is retrieved from the disk cache, resulting in a denial of service.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

released

6.5-1ubuntu1
esm-infra/focal

released

4.10-1ubuntu1.12
focal

released

4.10-1ubuntu1.12
jammy

released

5.7-0ubuntu0.22.04.4
lunar

ignored

end of life, was deferred [2024-01-26]
mantic

released

6.1-2ubuntu1.3
noble

released

6.5-1ubuntu1
oracular

released

6.5-1ubuntu1
plucky

released

6.5-1ubuntu1

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

DNE

esm-infra/bionic

needed

esm-infra/focal

DNE

esm-infra/xenial

needed

focal

DNE

jammy

DNE

lunar

DNE

mantic

DNE

noble

DNE

Показывать по

EPSS

Процентиль: 81%
0.01599
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
около 2 лет назад

A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the worker process when a large header is retrieved from the disk cache, resulting in a denial of service.

CVSS3: 7.5
nvd
около 2 лет назад

A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the worker process when a large header is retrieved from the disk cache, resulting in a denial of service.

CVSS3: 7.5
msrc
2 месяца назад

Squid: dos against http and https

CVSS3: 7.5
debian
около 2 лет назад

A flaw was found in Squid. The limits applied for validation of HTTP r ...

oracle-oval
почти 2 года назад

ELSA-2023-7668: squid:4 security update (IMPORTANT)

EPSS

Процентиль: 81%
0.01599
Низкий

7.5 High

CVSS3