PT-2023-7926 · Squid+8 · Squid+9

·

CVE-2023-49288

·

Publicado

2023-11-22

·

Atualizado

2024-08-12

CVSS v3.1

8.6

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Squid versions 3.5 through 5.9
Description Squid is a caching proxy for the Web that supports HTTP, HTTPS, FTP, and more. The affected versions of Squid are subject to a Use-After-Free bug, which can lead to a Denial of Service attack via collapsed forwarding. This issue arises when Squid is configured with "collapsed forwarding on". Configurations with "collapsed forwarding off" or without a "collapsed forwarding" directive are not vulnerable.
Recommendations For Squid versions 3.5 through 5.9, users are advised to upgrade to version 6.0.1 to fix the bug. For users unable to upgrade, it is recommended to remove all collapsed forwarding lines from their squid.conf as a temporary workaround.

Exploit

Correção

DoS

Use After Free

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2024-9370
AZL-32073
BDU:2023-09004
CESA-2023_7668
CVE-2023-49288
GHSA-RJ5H-46J6-Q2G5
MGASA-2024-0126
OPENSUSE-SU-2024:13631-1
RHSA-2023:7465
RHSA-2023:7668
RHSA-2023_7465
RHSA-2023_7668
USN-6728-1
USN-6728-2
USN-6728-3

Produtos afetados

Alt Linux
Centos
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Squid
Squid Cache
Ubuntu