[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-4122-1 squid3 -- squid3

ID: oval:org.secpod.oval:def:603278Date: (C)2018-02-28   (M)2023-12-20
Class: PATCHFamily: unix




Several vulnerabilities have been discovered in Squid3, a fully featured web proxy cache. The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2018-1000024 Louis Dion-Marcil discovered that Squid does not properly handle processing of certain ESI responses. A remote server delivering certain ESI response syntax can take advantage of this flaw to cause a denial of service for all clients accessing the Squid service. This problem is limited to the Squid custom ESI parser. A remote attacker can take advantage of this flaw to cause a denial of service for all clients accessing the Squid service

Platform:
Debian 8.x
Debian 9.x
Product:
squid3
squid
Reference:
DSA-4122-1
CVE-2018-1000024
CVE-2018-1000027
CVE    2
CVE-2018-1000024
CVE-2018-1000027
CPE    7
cpe:/o:debian:debian_linux:9.0
cpe:/o:debian:debian_linux:8.x
cpe:/o:debian:debian_linux:9.x
cpe:/a:squid-cache:squid
...

© SecPod Technologies