Логотип exploitDog
bind:"CVE-2023-46724" OR bind:"CVE-2023-46728" OR bind:"CVE-2023-49285" OR bind:"CVE-2023-49286"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2023-46724" OR bind:"CVE-2023-46728" OR bind:"CVE-2023-49285" OR bind:"CVE-2023-49286"

Количество 35

Количество 35

rocky логотип

RLSA-2024:0046

около 2 лет назад

Important: squid:4 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-0071

около 2 лет назад

ELSA-2024-0071: squid security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-0046

около 2 лет назад

ELSA-2024-0046: squid:4 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-1787

почти 2 года назад

ELSA-2024-1787: squid security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2023-46724

около 2 лет назад

Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This bug is fixed in Squid version 6.4. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. Those who you use a prepackaged version of Squid should refer to the package vendor for availability information on updated packages.

CVSS3: 8.6
EPSS: Низкий
redhat логотип

CVE-2023-46724

около 2 лет назад

Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This bug is fixed in Squid version 6.4. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. Those who you use a prepackaged version of Squid should refer to the package vendor for availability information on updated packages.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-46724

около 2 лет назад

Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This bug is fixed in Squid version 6.4. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. Those who you use a prepackaged version of Squid should refer to the package vendor for availability information on updated packages.

CVSS3: 8.6
EPSS: Низкий
debian логотип

CVE-2023-46724

около 2 лет назад

Squid is a caching proxy for the Web. Due to an Improper Validation of ...

CVSS3: 8.6
EPSS: Низкий
fstec логотип

BDU:2023-07699

около 2 лет назад

Уязвимость прокси-сервера Squid, связанная с ошибками при проверке сертификата SSL/TLS, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.6
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4825-1

около 2 лет назад

Security update for squid

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4724-1

около 2 лет назад

Security update for squid

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4698-1

около 2 лет назад

Security update for squid

EPSS: Низкий
redos логотип

ROS-20240725-02

больше 1 года назад

Уязвимость squid

CVSS3: 8.6
EPSS: Низкий
ubuntu логотип

CVE-2023-46728

около 2 лет назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of Service attack against Squid's Gopher gateway. The gopher protocol is always available and enabled in Squid prior to Squid 6.0.1. Responses triggering this bug are possible to be received from any gopher server, even those without malicious intent. Gopher support has been removed in Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should reject all gopher URL requests.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2023-46728

больше 2 лет назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of Service attack against Squid's Gopher gateway. The gopher protocol is always available and enabled in Squid prior to Squid 6.0.1. Responses triggering this bug are possible to be received from any gopher server, even those without malicious intent. Gopher support has been removed in Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should reject all gopher URL requests.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-46728

около 2 лет назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of Service attack against Squid's Gopher gateway. The gopher protocol is always available and enabled in Squid prior to Squid 6.0.1. Responses triggering this bug are possible to be received from any gopher server, even those without malicious intent. Gopher support has been removed in Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should reject all gopher URL requests.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-46728

около 2 лет назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4384-1

около 2 лет назад

Security update for squid

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4381-1

около 2 лет назад

Security update for squid

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4380-1

около 2 лет назад

Security update for squid

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2024:0046

Important: squid:4 security update

около 2 лет назад
oracle-oval логотип
ELSA-2024-0071

ELSA-2024-0071: squid security update (IMPORTANT)

около 2 лет назад
oracle-oval логотип
ELSA-2024-0046

ELSA-2024-0046: squid:4 security update (IMPORTANT)

около 2 лет назад
oracle-oval логотип
ELSA-2024-1787

ELSA-2024-1787: squid security update (IMPORTANT)

почти 2 года назад
ubuntu логотип
CVE-2023-46724

Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This bug is fixed in Squid version 6.4. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. Those who you use a prepackaged version of Squid should refer to the package vendor for availability information on updated packages.

CVSS3: 8.6
0%
Низкий
около 2 лет назад
redhat логотип
CVE-2023-46724

Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This bug is fixed in Squid version 6.4. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. Those who you use a prepackaged version of Squid should refer to the package vendor for availability information on updated packages.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-46724

Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This bug is fixed in Squid version 6.4. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. Those who you use a prepackaged version of Squid should refer to the package vendor for availability information on updated packages.

CVSS3: 8.6
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-46724

Squid is a caching proxy for the Web. Due to an Improper Validation of ...

CVSS3: 8.6
0%
Низкий
около 2 лет назад
fstec логотип
BDU:2023-07699

Уязвимость прокси-сервера Squid, связанная с ошибками при проверке сертификата SSL/TLS, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.6
0%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:4825-1

Security update for squid

около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:4724-1

Security update for squid

около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:4698-1

Security update for squid

около 2 лет назад
redos логотип
ROS-20240725-02

Уязвимость squid

CVSS3: 8.6
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2023-46728

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of Service attack against Squid's Gopher gateway. The gopher protocol is always available and enabled in Squid prior to Squid 6.0.1. Responses triggering this bug are possible to be received from any gopher server, even those without malicious intent. Gopher support has been removed in Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should reject all gopher URL requests.

CVSS3: 7.5
2%
Низкий
около 2 лет назад
redhat логотип
CVE-2023-46728

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of Service attack against Squid's Gopher gateway. The gopher protocol is always available and enabled in Squid prior to Squid 6.0.1. Responses triggering this bug are possible to be received from any gopher server, even those without malicious intent. Gopher support has been removed in Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should reject all gopher URL requests.

CVSS3: 7.5
2%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-46728

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of Service attack against Squid's Gopher gateway. The gopher protocol is always available and enabled in Squid prior to Squid 6.0.1. Responses triggering this bug are possible to be received from any gopher server, even those without malicious intent. Gopher support has been removed in Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should reject all gopher URL requests.

CVSS3: 7.5
2%
Низкий
около 2 лет назад
debian логотип
CVE-2023-46728

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and ...

CVSS3: 7.5
2%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:4384-1

Security update for squid

около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:4381-1

Security update for squid

около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:4380-1

Security update for squid

около 2 лет назад

Уязвимостей на страницу