Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 13

Количество 13

ubuntu логотип

CVE-2024-23638

больше 2 лет назад

Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows a trusted client to perform Denial of Service when generating error pages for Client Manager reports. Squid older than 5.0.5 have not been tested and should be assumed to be vulnerable. All Squid-5.x up to and including 5.9 are vulnerable. All Squid-6.x up to and including 6.5 are vulnerable. This bug is fixed by Squid version 6.6. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. As a workaround, prevent access to Cache Manager using Squid's main access control: `http_access deny manager`.

CVSS3: 6.5
EPSS: Средний
redhat логотип

CVE-2024-23638

больше 2 лет назад

Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows a trusted client to perform Denial of Service when generating error pages for Client Manager reports. Squid older than 5.0.5 have not been tested and should be assumed to be vulnerable. All Squid-5.x up to and including 5.9 are vulnerable. All Squid-6.x up to and including 6.5 are vulnerable. This bug is fixed by Squid version 6.6. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. As a workaround, prevent access to Cache Manager using Squid's main access control: `http_access deny manager`.

CVSS3: 6.5
EPSS: Средний
nvd логотип

CVE-2024-23638

больше 2 лет назад

Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows a trusted client to perform Denial of Service when generating error pages for Client Manager reports. Squid older than 5.0.5 have not been tested and should be assumed to be vulnerable. All Squid-5.x up to and including 5.9 are vulnerable. All Squid-6.x up to and including 6.5 are vulnerable. This bug is fixed by Squid version 6.6. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. As a workaround, prevent access to Cache Manager using Squid's main access control: `http_access deny manager`.

CVSS3: 6.5
EPSS: Средний
debian логотип

CVE-2024-23638

больше 2 лет назад

Squid is a caching proxy for the Web. Due to an expired pointer refere ...

CVSS3: 6.5
EPSS: Средний
fstec логотип

BDU:2024-00895

больше 2 лет назад

Уязвимость прокси-сервера Squid, связанная с разыменованием указателя с истекшим сроком действия, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.5
EPSS: Средний
suse-cvrf логотип

SUSE-SU-2024:0455-1

больше 2 лет назад

Security update for squid

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0298-1

больше 2 лет назад

Security update for squid

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0296-1

больше 2 лет назад

Security update for squid

EPSS: Низкий
redos логотип

ROS-20240329-02

больше 2 лет назад

Уязвимость squid

CVSS3: 6.5
EPSS: Средний
rocky логотип

RLSA-2024:9644

больше 1 года назад

Important: squid:4 security update

EPSS: Низкий
rocky логотип

RLSA-2024:4861

около 2 лет назад

Moderate: squid security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-9644

больше 1 года назад

ELSA-2024-9644: squid security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-4861

около 2 лет назад

ELSA-2024-4861: squid security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-23638

Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows a trusted client to perform Denial of Service when generating error pages for Client Manager reports. Squid older than 5.0.5 have not been tested and should be assumed to be vulnerable. All Squid-5.x up to and including 5.9 are vulnerable. All Squid-6.x up to and including 6.5 are vulnerable. This bug is fixed by Squid version 6.6. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. As a workaround, prevent access to Cache Manager using Squid's main access control: `http_access deny manager`.

CVSS3: 6.5
60%
Средний
больше 2 лет назад
redhat логотип
CVE-2024-23638

Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows a trusted client to perform Denial of Service when generating error pages for Client Manager reports. Squid older than 5.0.5 have not been tested and should be assumed to be vulnerable. All Squid-5.x up to and including 5.9 are vulnerable. All Squid-6.x up to and including 6.5 are vulnerable. This bug is fixed by Squid version 6.6. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. As a workaround, prevent access to Cache Manager using Squid's main access control: `http_access deny manager`.

CVSS3: 6.5
60%
Средний
больше 2 лет назад
nvd логотип
CVE-2024-23638

Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows a trusted client to perform Denial of Service when generating error pages for Client Manager reports. Squid older than 5.0.5 have not been tested and should be assumed to be vulnerable. All Squid-5.x up to and including 5.9 are vulnerable. All Squid-6.x up to and including 6.5 are vulnerable. This bug is fixed by Squid version 6.6. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. As a workaround, prevent access to Cache Manager using Squid's main access control: `http_access deny manager`.

CVSS3: 6.5
60%
Средний
больше 2 лет назад
debian логотип
CVE-2024-23638

Squid is a caching proxy for the Web. Due to an expired pointer refere ...

CVSS3: 6.5
60%
Средний
больше 2 лет назад
fstec логотип
BDU:2024-00895

Уязвимость прокси-сервера Squid, связанная с разыменованием указателя с истекшим сроком действия, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.5
60%
Средний
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:0455-1

Security update for squid

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:0298-1

Security update for squid

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:0296-1

Security update for squid

больше 2 лет назад
redos логотип
ROS-20240329-02

Уязвимость squid

CVSS3: 6.5
60%
Средний
больше 2 лет назад
rocky логотип
RLSA-2024:9644

Important: squid:4 security update

больше 1 года назад
rocky логотип
RLSA-2024:4861

Moderate: squid security update

около 2 лет назад
oracle-oval логотип
ELSA-2024-9644

ELSA-2024-9644: squid security update (IMPORTANT)

больше 1 года назад
oracle-oval логотип
ELSA-2024-4861

ELSA-2024-4861: squid security update (MODERATE)

около 2 лет назад

Уязвимостей на страницу