CVE-2023-46848
published 2023-11-03CVE-2023-46848: Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs…
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
10.22%
95.2th percentile
Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs from FTP Native input.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | squid | < squid 5.7-2+deb12u1 (bookworm) | squid 5.7-2+deb12u1 (bookworm) |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| squid-cache | squid | >= 5.0.3 < 6.4 | 6.4 |
| squid | squid | >= 0 < 5.7-2+deb12u1 | 5.7-2+deb12u1 |
| squid | squid | >= 0 < 6.5-1 | 6.5-1 |
| squid | squid | >= 0 < 6.5-1 | 6.5-1 |
| squid | squid | >= 0 < 4.10-1ubuntu1.8 | 4.10-1ubuntu1.8 |
| squid | squid | >= 0 < 5.7-0ubuntu0.22.04.2 | 5.7-0ubuntu0.22.04.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_oracle9.1CRITICAL
vendor_debian8.6HIGH
vendor_redhat8.6HIGH
vendor_ubuntu8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
squid vulnerabilities
osv·2023-11-21·CVSS 7.5
CVE-2023-46724 [HIGH] squid vulnerabilities
squid vulnerabilities
Joshua Rogers discovered that Squid incorrectly handled validating certain
SSL certificates. A remote attacker could possibly use this issue to cause
Squid to crash, resulting in a denial of service. This issue only affected
Ubuntu 22.04 LTS, Ubuntu 23.04, and Ubuntu 23.10. (CVE-2023-46724)
Joshua Rogers discovered that Squid incorrectly handled the Gopher
protocol. A remote attacker could possibly use this issue to cause Squid to
crash, resulting in a denial of service. Gopher support has been disabled
in this update. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04
LTS, and Ubuntu 23.04. (CVE-2023-46728)
Keran Mu and Jianjun Chen discovered that Squid incorrectly handled the
chunked decoder. A remote attacker could possibly use this issue to perform
HTTP r
OSV
CVE-2023-46848: Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ftp:
osv·2023-11-03·CVSS 7.5
CVE-2023-46848 [HIGH] CVE-2023-46848: Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ftp:
Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs from FTP Native input.
Ubuntu
Squid vulnerabilities
vendor_ubuntu·2023-11-21·CVSS 8.6
CVE-2023-46724 [HIGH] Squid vulnerabilities
Title: Squid vulnerabilities
Summary: Several security issues were fixed in Squid.
Joshua Rogers discovered that Squid incorrectly handled validating certain
SSL certificates. A remote attacker could possibly use this issue to cause
Squid to crash, resulting in a denial of service. This issue only affected
Ubuntu 22.04 LTS, Ubuntu 23.04, and Ubuntu 23.10. (CVE-2023-46724)
Joshua Rogers discovered that Squid incorrectly handled the Gopher
protocol. A remote attacker could possibly use this issue to cause Squid to
crash, resulting in a denial of service. Gopher support has been disabled
in this update. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04
LTS, and Ubuntu 23.04. (CVE-2023-46728)
Keran Mu and Jianjun Chen discovered that Squid incorrectly handled the
chunked decoder. A r
Red Hat
squid: denial of Service in FTP
vendor_redhat·2023-10-19·CVSS 8.6
CVE-2023-46848 [HIGH] CWE-681 squid: denial of Service in FTP
squid: denial of Service in FTP
Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs from FTP Native input.
Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs from FTP Native input.
Package: squid (Red Hat Enterprise Linux 6) - Not affected
Package: squid (Red Hat Enterprise Linux 7) - Not affected
Package: squid:4/squid (Red Hat Enterprise Linux 8) - Not affected
Oracle
Oracle Oracle Communications Risk Matrix: Policy (GNU Libtasn1) — CVE-2021-46848
vendor_oracle·2023-04-15·CVSS 9.1
CVE-2021-46848 [CRITICAL] Oracle Oracle Communications Risk Matrix: Policy (GNU Libtasn1) — CVE-2021-46848
Oracle Oracle Communications Risk Matrix: Policy (GNU Libtasn1) vulnerability
CVE: CVE-2021-46848
CVSS: 9.1
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Debian
CVE-2023-46848: squid - Squid is vulnerable to Denial of Service, where a remote attacker can perform D...
vendor_debian·2023·CVSS 8.6
CVE-2023-46848 [HIGH] CVE-2023-46848: squid - Squid is vulnerable to Denial of Service, where a remote attacker can perform D...
Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs from FTP Native input.
Scope: local
bookworm: resolved (fixed in 5.7-2+deb12u1)
bullseye: resolved
forky: resolved (fixed in 6.5-1)
sid: resolved (fixed in 6.5-1)
trixie: resolved (fixed in 6.5-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:6266https://access.redhat.com/errata/RHSA-2023:6268https://access.redhat.com/errata/RHSA-2023:6748https://access.redhat.com/security/cve/CVE-2023-46848https://bugzilla.redhat.com/show_bug.cgi?id=2245919https://github.com/squid-cache/squid/security/advisories/GHSA-2g3c-pg7q-g59whttps://access.redhat.com/errata/RHSA-2023:6266https://access.redhat.com/errata/RHSA-2023:6268https://access.redhat.com/errata/RHSA-2023:6748https://access.redhat.com/security/cve/CVE-2023-46848https://bugzilla.redhat.com/show_bug.cgi?id=2245919https://github.com/squid-cache/squid/security/advisories/GHSA-2g3c-pg7q-g59whttps://security.netapp.com/advisory/ntap-20231214-0005/
2023-11-03
Published