CVE-2023-46724 — Out-of-bounds Read in Squid
CWE-125 — Out-of-bounds ReadCWE-129 — Improper Validation of Array IndexCWE-786 — Access of Memory Location Before Start of BufferCWE-823 — Use of Out-of-range Pointer OffsetCWE-1285 — Improper Validation of Specified Index, Position, or Offset in InputCWE-295 — Improper Certificate Validation7 documents6 sources
Severity
7.5HIGHNVD
CNA8.6
EPSS
0.4%
top 40.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 1
Latest updateNov 21
Description
Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This b…
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6