Логотип exploitDog
bind: "CVE-2024-23638"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2024-23638"

Количество 12

Количество 12

ubuntu логотип

CVE-2024-23638

почти 2 года назад

Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows a trusted client to perform Denial of Service when generating error pages for Client Manager reports. Squid older than 5.0.5 have not been tested and should be assumed to be vulnerable. All Squid-5.x up to and including 5.9 are vulnerable. All Squid-6.x up to and including 6.5 are vulnerable. This bug is fixed by Squid version 6.6. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. As a workaround, prevent access to Cache Manager using Squid's main access control: `http_access deny manager`.

CVSS3: 6.5
EPSS: Средний
redhat логотип

CVE-2024-23638

почти 2 года назад

Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows a trusted client to perform Denial of Service when generating error pages for Client Manager reports. Squid older than 5.0.5 have not been tested and should be assumed to be vulnerable. All Squid-5.x up to and including 5.9 are vulnerable. All Squid-6.x up to and including 6.5 are vulnerable. This bug is fixed by Squid version 6.6. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. As a workaround, prevent access to Cache Manager using Squid's main access control: `http_access deny manager`.

CVSS3: 6.5
EPSS: Средний
nvd логотип

CVE-2024-23638

почти 2 года назад

Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows a trusted client to perform Denial of Service when generating error pages for Client Manager reports. Squid older than 5.0.5 have not been tested and should be assumed to be vulnerable. All Squid-5.x up to and including 5.9 are vulnerable. All Squid-6.x up to and including 6.5 are vulnerable. This bug is fixed by Squid version 6.6. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. As a workaround, prevent access to Cache Manager using Squid's main access control: `http_access deny manager`.

CVSS3: 6.5
EPSS: Средний
debian логотип

CVE-2024-23638

почти 2 года назад

Squid is a caching proxy for the Web. Due to an expired pointer refere ...

CVSS3: 6.5
EPSS: Средний
fstec логотип

BDU:2024-00895

почти 2 года назад

Уязвимость прокси-сервера Squid, связанная с разыменованием указателя с истекшим сроком действия, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.5
EPSS: Средний
suse-cvrf логотип

SUSE-SU-2024:0455-1

больше 1 года назад

Security update for squid

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0298-1

почти 2 года назад

Security update for squid

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0296-1

почти 2 года назад

Security update for squid

EPSS: Низкий
redos логотип

ROS-20240329-02

больше 1 года назад

Уязвимость squid

CVSS3: 6.5
EPSS: Средний
rocky логотип

RLSA-2024:4861

больше 1 года назад

Moderate: squid security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-9644

12 месяцев назад

ELSA-2024-9644: squid security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-4861

больше 1 года назад

ELSA-2024-4861: squid security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-23638

Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows a trusted client to perform Denial of Service when generating error pages for Client Manager reports. Squid older than 5.0.5 have not been tested and should be assumed to be vulnerable. All Squid-5.x up to and including 5.9 are vulnerable. All Squid-6.x up to and including 6.5 are vulnerable. This bug is fixed by Squid version 6.6. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. As a workaround, prevent access to Cache Manager using Squid's main access control: `http_access deny manager`.

CVSS3: 6.5
14%
Средний
почти 2 года назад
redhat логотип
CVE-2024-23638

Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows a trusted client to perform Denial of Service when generating error pages for Client Manager reports. Squid older than 5.0.5 have not been tested and should be assumed to be vulnerable. All Squid-5.x up to and including 5.9 are vulnerable. All Squid-6.x up to and including 6.5 are vulnerable. This bug is fixed by Squid version 6.6. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. As a workaround, prevent access to Cache Manager using Squid's main access control: `http_access deny manager`.

CVSS3: 6.5
14%
Средний
почти 2 года назад
nvd логотип
CVE-2024-23638

Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows a trusted client to perform Denial of Service when generating error pages for Client Manager reports. Squid older than 5.0.5 have not been tested and should be assumed to be vulnerable. All Squid-5.x up to and including 5.9 are vulnerable. All Squid-6.x up to and including 6.5 are vulnerable. This bug is fixed by Squid version 6.6. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. As a workaround, prevent access to Cache Manager using Squid's main access control: `http_access deny manager`.

CVSS3: 6.5
14%
Средний
почти 2 года назад
debian логотип
CVE-2024-23638

Squid is a caching proxy for the Web. Due to an expired pointer refere ...

CVSS3: 6.5
14%
Средний
почти 2 года назад
fstec логотип
BDU:2024-00895

Уязвимость прокси-сервера Squid, связанная с разыменованием указателя с истекшим сроком действия, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.5
14%
Средний
почти 2 года назад
suse-cvrf логотип
SUSE-SU-2024:0455-1

Security update for squid

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:0298-1

Security update for squid

почти 2 года назад
suse-cvrf логотип
SUSE-SU-2024:0296-1

Security update for squid

почти 2 года назад
redos логотип
ROS-20240329-02

Уязвимость squid

CVSS3: 6.5
14%
Средний
больше 1 года назад
rocky логотип
RLSA-2024:4861

Moderate: squid security update

больше 1 года назад
oracle-oval логотип
ELSA-2024-9644

ELSA-2024-9644: squid security update (IMPORTANT)

12 месяцев назад
oracle-oval логотип
ELSA-2024-4861

ELSA-2024-4861: squid security update (MODERATE)

больше 1 года назад

Уязвимостей на страницу