Severity
7.5HIGHNVD
CNA8.6
EPSS
0.4%
top 40.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 1
Latest updateNov 21

Description

Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This b

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDsquid-cache/squid3.3.0.16.4
Debiansquid/squid< 4.13-10+deb11u3+3
Ubuntusquid/squid< 4.10-1ubuntu1.8+1
CVEListV5squid-cache/squid>= 3.3.0.1, < 6.4

Patches

🔴Vulnerability Details

3
OSV
squid vulnerabilities2023-11-21
OSV
CVE-2023-46724: Squid is a caching proxy for the Web2023-11-01
CVEList
SQUID-2023:4 Denial of Service in SSL Certificate validation2023-11-01

📋Vendor Advisories

3
Ubuntu
Squid vulnerabilities2023-11-21
Red Hat
squid: Denial of Service in SSL Certificate validation2023-11-01
Debian
CVE-2023-46724: squid - Squid is a caching proxy for the Web. Due to an Improper Validation of Specified...2023