Логотип exploitDog
bind: "CVE-2024-23638"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2024-23638"

Количество 12

Количество 12

ubuntu логотип

CVE-2024-23638

больше 1 года назад

Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows a trusted client to perform Denial of Service when generating error pages for Client Manager reports. Squid older than 5.0.5 have not been tested and should be assumed to be vulnerable. All Squid-5.x up to and including 5.9 are vulnerable. All Squid-6.x up to and including 6.5 are vulnerable. This bug is fixed by Squid version 6.6. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. As a workaround, prevent access to Cache Manager using Squid's main access control: `http_access deny manager`.

CVSS3: 6.5
EPSS: Средний
redhat логотип

CVE-2024-23638

больше 1 года назад

Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows a trusted client to perform Denial of Service when generating error pages for Client Manager reports. Squid older than 5.0.5 have not been tested and should be assumed to be vulnerable. All Squid-5.x up to and including 5.9 are vulnerable. All Squid-6.x up to and including 6.5 are vulnerable. This bug is fixed by Squid version 6.6. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. As a workaround, prevent access to Cache Manager using Squid's main access control: `http_access deny manager`.

CVSS3: 6.5
EPSS: Средний
nvd логотип

CVE-2024-23638

больше 1 года назад

Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows a trusted client to perform Denial of Service when generating error pages for Client Manager reports. Squid older than 5.0.5 have not been tested and should be assumed to be vulnerable. All Squid-5.x up to and including 5.9 are vulnerable. All Squid-6.x up to and including 6.5 are vulnerable. This bug is fixed by Squid version 6.6. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. As a workaround, prevent access to Cache Manager using Squid's main access control: `http_access deny manager`.

CVSS3: 6.5
EPSS: Средний
debian логотип

CVE-2024-23638

больше 1 года назад

Squid is a caching proxy for the Web. Due to an expired pointer refere ...

CVSS3: 6.5
EPSS: Средний
fstec логотип

BDU:2024-00895

больше 1 года назад

Уязвимость прокси-сервера Squid, связанная с разыменованием указателя с истекшим сроком действия, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.5
EPSS: Средний
suse-cvrf логотип

SUSE-SU-2024:0455-1

больше 1 года назад

Security update for squid

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0298-1

больше 1 года назад

Security update for squid

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0296-1

больше 1 года назад

Security update for squid

EPSS: Низкий
redos логотип

ROS-20240329-02

около 1 года назад

Уязвимость squid

CVSS3: 6.5
EPSS: Средний
rocky логотип

RLSA-2024:4861

11 месяцев назад

Moderate: squid security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-9644

7 месяцев назад

ELSA-2024-9644: squid security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-4861

11 месяцев назад

ELSA-2024-4861: squid security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-23638

Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows a trusted client to perform Denial of Service when generating error pages for Client Manager reports. Squid older than 5.0.5 have not been tested and should be assumed to be vulnerable. All Squid-5.x up to and including 5.9 are vulnerable. All Squid-6.x up to and including 6.5 are vulnerable. This bug is fixed by Squid version 6.6. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. As a workaround, prevent access to Cache Manager using Squid's main access control: `http_access deny manager`.

CVSS3: 6.5
15%
Средний
больше 1 года назад
redhat логотип
CVE-2024-23638

Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows a trusted client to perform Denial of Service when generating error pages for Client Manager reports. Squid older than 5.0.5 have not been tested and should be assumed to be vulnerable. All Squid-5.x up to and including 5.9 are vulnerable. All Squid-6.x up to and including 6.5 are vulnerable. This bug is fixed by Squid version 6.6. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. As a workaround, prevent access to Cache Manager using Squid's main access control: `http_access deny manager`.

CVSS3: 6.5
15%
Средний
больше 1 года назад
nvd логотип
CVE-2024-23638

Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows a trusted client to perform Denial of Service when generating error pages for Client Manager reports. Squid older than 5.0.5 have not been tested and should be assumed to be vulnerable. All Squid-5.x up to and including 5.9 are vulnerable. All Squid-6.x up to and including 6.5 are vulnerable. This bug is fixed by Squid version 6.6. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. As a workaround, prevent access to Cache Manager using Squid's main access control: `http_access deny manager`.

CVSS3: 6.5
15%
Средний
больше 1 года назад
debian логотип
CVE-2024-23638

Squid is a caching proxy for the Web. Due to an expired pointer refere ...

CVSS3: 6.5
15%
Средний
больше 1 года назад
fstec логотип
BDU:2024-00895

Уязвимость прокси-сервера Squid, связанная с разыменованием указателя с истекшим сроком действия, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.5
15%
Средний
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:0455-1

Security update for squid

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:0298-1

Security update for squid

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:0296-1

Security update for squid

больше 1 года назад
redos логотип
ROS-20240329-02

Уязвимость squid

CVSS3: 6.5
15%
Средний
около 1 года назад
rocky логотип
RLSA-2024:4861

Moderate: squid security update

11 месяцев назад
oracle-oval логотип
ELSA-2024-9644

ELSA-2024-9644: squid security update (IMPORTANT)

7 месяцев назад
oracle-oval логотип
ELSA-2024-4861

ELSA-2024-4861: squid security update (MODERATE)

11 месяцев назад

Уязвимостей на страницу