[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-5637-1 squid -- squid

ID: oval:org.secpod.oval:def:613004Date: (C)2024-03-28   (M)2024-04-25
Class: PATCHFamily: unix




Several security vulnerabilities have been discovered in Squid, a full featured web proxy cache. Due to programming errors in Squid"s HTTP request parsing, remote attackers may be able to execute a denial of service attack by sending large X-Forwarded-For header or trigger a stack buffer overflow while performing HTTP Digest authentication. Other issues facilitate request smuggling past a firewall or a denial of service against Squid"s Helper process management. In regard to CVE-2023-46728: Please note that support for the Gopher protocol has simply been removed in future Squid versions. There are no plans by the upstream developers of Squid to fix this issue. We recommend to reject all Gopher URL requests instead.

Platform:
Debian 12.x
Debian 11.x
Product:
squid
Reference:
DSA-5637-1
CVE-2023-46724
CVE-2023-46846
CVE-2023-46847
CVE-2023-49285
CVE-2023-49286
CVE-2023-50269
CVE-2024-23638
CVE-2024-25617
CVE-2023-46848
CVE-2024-25111
CVE-2023-46728
CVE    11
CVE-2023-46728
CVE-2023-46847
CVE-2023-46848
CVE-2023-46724
...
CPE    2
cpe:/a:squid-cache:squid
cpe:/o:debian:debian_linux:11.x

© SecPod Technologies