cbcvebase.
CVE-2023-5824
published 2023-11-03

CVE-2023-5824: A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the worker process when a large header is retrieved from the disk cache, resulting in a denial of service.

Affected

15 ranges
VendorProductVersion rangeFixed in
debiansquid< squid 5.7-2+deb12u3 (bookworm)squid 5.7-2+deb12u3 (bookworm)
msrcazl3_squid_6.13-1_on_azure_linux_3.0
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
squid-cachesquid< 6.46.4
squidsquid>= 0 < 4.13-10+deb11u54.13-10+deb11u5
squidsquid>= 0 < 5.7-2+deb12u35.7-2+deb12u3
squidsquid>= 0 < 6.5-16.5-1
squidsquid>= 0 < 6.5-16.5-1
squidsquid>= 0 < 4.10-1ubuntu1.114.10-1ubuntu1.11
squidsquid>= 0 < 4.10-1ubuntu1.124.10-1ubuntu1.12
squidsquid>= 0 < 4.10-1ubuntu1.104.10-1ubuntu1.10
squidsquid>= 0 < 5.7-0ubuntu0.22.04.45.7-0ubuntu0.22.04.4

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH