CVE-2023-46847
published 2023-11-03CVE-2023-46847: Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory…
PriorityP265high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
85.83%
99.7th percentile
Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | squid | < squid 5.7-2+deb12u1 (bookworm) | squid 5.7-2+deb12u1 (bookworm) |
| msrc | azl3_squid_6.13-1_on_azure_linux_3.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_for_arm_64 | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_power_little_endian | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| squid-cache | squid | >= 3.2.0.1 < 6.4 | 6.4 |
| squid | squid | >= 0 < 4.13-10+deb11u3 | 4.13-10+deb11u3 |
| squid | squid | >= 0 < 5.7-2+deb12u1 | 5.7-2+deb12u1 |
Detection & IOCsextracted from sources · hover to see the quote
- →Target Squid instances configured to accept HTTP Digest Authentication — the vulnerability is only exploitable when this authentication method is enabled ↗
- →Monitor for anomalously large HTTP Digest Authentication headers/payloads (up to 2 MB) sent to Squid proxy — this is the attack vector for the heap buffer overflow ↗
- →Watch for unexpected Squid process crashes or denial-of-service conditions, which may indicate exploitation attempts against the HTTP Digest Authentication handler ↗
- ·The vulnerability is only exploitable when Squid is explicitly configured to accept HTTP Digest Authentication; deployments not using Digest Authentication are not affected ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian8.6HIGH
vendor_msrc8.6HIGH
vendor_redhat8.6HIGH
vendor_ubuntu8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
squid3 vulnerabilities
osv·2023-12-11·CVSS 7.5
CVE-2023-46728 [HIGH] squid3 vulnerabilities
squid3 vulnerabilities
USN-6500-1 fixed several vulnerabilities in Squid. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
Joshua Rogers discovered that Squid incorrectly handled the Gopher
protocol. A remote attacker could possibly use this issue to cause Squid to
crash, resulting in a denial of service. Gopher support has been disabled
in this update. (CVE-2023-46728)
Joshua Rogers discovered that Squid incorrectly handled HTTP Digest
Authentication. A remote attacker could possibly use this issue to cause
Squid to crash, resulting in a denial of service. (CVE-2023-46847)
OSV
squid vulnerabilities
osv·2023-11-21·CVSS 7.5
CVE-2023-46724 [HIGH] squid vulnerabilities
squid vulnerabilities
Joshua Rogers discovered that Squid incorrectly handled validating certain
SSL certificates. A remote attacker could possibly use this issue to cause
Squid to crash, resulting in a denial of service. This issue only affected
Ubuntu 22.04 LTS, Ubuntu 23.04, and Ubuntu 23.10. (CVE-2023-46724)
Joshua Rogers discovered that Squid incorrectly handled the Gopher
protocol. A remote attacker could possibly use this issue to cause Squid to
crash, resulting in a denial of service. Gopher support has been disabled
in this update. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04
LTS, and Ubuntu 23.04. (CVE-2023-46728)
Keran Mu and Jianjun Chen discovered that Squid incorrectly handled the
chunked decoder. A remote attacker could possibly use this issue to perform
HTTP r
OSV
CVE-2023-46847: Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap
osv·2023-11-03·CVSS 7.5
CVE-2023-46847 [HIGH] CVE-2023-46847: Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap
Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.
Ubuntu
Squid vulnerabilities
vendor_ubuntu·2023-12-11·CVSS 7.5
CVE-2023-46847 [HIGH] Squid vulnerabilities
Title: Squid vulnerabilities
Summary: Several security issues were fixed in Squid.
USN-6500-1 fixed several vulnerabilities in Squid. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
Joshua Rogers discovered that Squid incorrectly handled the Gopher
protocol. A remote attacker could possibly use this issue to cause Squid to
crash, resulting in a denial of service. Gopher support has been disabled
in this update. (CVE-2023-46728)
Joshua Rogers discovered that Squid incorrectly handled HTTP Digest
Authentication. A remote attacker could possibly use this issue to cause
Squid to crash, resulting in a denial of service. (CVE-2023-46847)
Instructions: In general, a standard system update will make all the necessary changes
Ubuntu
Squid vulnerabilities
vendor_ubuntu·2023-11-21·CVSS 8.6
CVE-2023-46724 [HIGH] Squid vulnerabilities
Title: Squid vulnerabilities
Summary: Several security issues were fixed in Squid.
Joshua Rogers discovered that Squid incorrectly handled validating certain
SSL certificates. A remote attacker could possibly use this issue to cause
Squid to crash, resulting in a denial of service. This issue only affected
Ubuntu 22.04 LTS, Ubuntu 23.04, and Ubuntu 23.10. (CVE-2023-46724)
Joshua Rogers discovered that Squid incorrectly handled the Gopher
protocol. A remote attacker could possibly use this issue to cause Squid to
crash, resulting in a denial of service. Gopher support has been disabled
in this update. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04
LTS, and Ubuntu 23.04. (CVE-2023-46728)
Keran Mu and Jianjun Chen discovered that Squid incorrectly handled the
chunked decoder. A r
Microsoft
Squid: denial of service in http digest authentication
vendor_msrc·2023-11-14·CVSS 8.6
CVE-2023-46847 [HIGH] CWE-120 Squid: denial of service in http digest authentication
Squid: denial of service in http digest authentication
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://lear
Red Hat
squid: Denial of Service in HTTP Digest Authentication
vendor_redhat·2023-10-19·CVSS 8.6
CVE-2023-46847 [HIGH] CWE-120 squid: Denial of Service in HTTP Digest Authentication
squid: Denial of Service in HTTP Digest Authentication
Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.
Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.
Debian
CVE-2023-46847: squid - Squid is vulnerable to a Denial of Service, where a remote attacker can perform...
vendor_debian·2023·CVSS 8.6
CVE-2023-46847 [HIGH] CVE-2023-46847: squid - Squid is vulnerable to a Denial of Service, where a remote attacker can perform...
Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.
Scope: local
bookworm: resolved (fixed in 5.7-2+deb12u1)
bullseye: resolved (fixed in 4.13-10+deb11u3)
forky: resolved (fixed in 6.5-1)
sid: resolved (fixed in 6.5-1)
trixie: resolved (fixed in 6.5-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:6266https://access.redhat.com/errata/RHSA-2023:6267https://access.redhat.com/errata/RHSA-2023:6268https://access.redhat.com/errata/RHSA-2023:6748https://access.redhat.com/errata/RHSA-2023:6801https://access.redhat.com/errata/RHSA-2023:6803https://access.redhat.com/errata/RHSA-2023:6804https://access.redhat.com/errata/RHSA-2023:6805https://access.redhat.com/errata/RHSA-2023:6810https://access.redhat.com/errata/RHSA-2023:6882https://access.redhat.com/errata/RHSA-2023:6884https://access.redhat.com/errata/RHSA-2023:7213https://access.redhat.com/errata/RHSA-2023:7576https://access.redhat.com/errata/RHSA-2023:7578https://access.redhat.com/security/cve/CVE-2023-46847https://bugzilla.redhat.com/show_bug.cgi?id=2245916https://github.com/squid-cache/squid/security/advisories/GHSA-phqj-m8gv-cq4ghttps://access.redhat.com/errata/RHSA-2023:6266https://access.redhat.com/errata/RHSA-2023:6267https://access.redhat.com/errata/RHSA-2023:6268https://access.redhat.com/errata/RHSA-2023:6748https://access.redhat.com/errata/RHSA-2023:6801https://access.redhat.com/errata/RHSA-2023:6803https://access.redhat.com/errata/RHSA-2023:6804https://access.redhat.com/errata/RHSA-2023:6805https://access.redhat.com/errata/RHSA-2023:6810https://access.redhat.com/errata/RHSA-2023:6882https://access.redhat.com/errata/RHSA-2023:6884https://access.redhat.com/errata/RHSA-2023:7213https://access.redhat.com/errata/RHSA-2023:7576https://access.redhat.com/errata/RHSA-2023:7578https://access.redhat.com/security/cve/CVE-2023-46847https://bugzilla.redhat.com/show_bug.cgi?id=2245916https://github.com/squid-cache/squid/security/advisories/GHSA-phqj-m8gv-cq4ghttps://lists.debian.org/debian-lts-announce/2024/01/msg00003.htmlhttps://security.netapp.com/advisory/ntap-20231130-0002/
2023-11-03
Published