CVE-2023-5824
published 2023-11-03CVE-2023-5824: A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
5.23%
91.6th percentile
A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the worker process when a large header is retrieved from the disk cache, resulting in a denial of service.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | squid | < squid 5.7-2+deb12u3 (bookworm) | squid 5.7-2+deb12u3 (bookworm) |
| msrc | azl3_squid_6.13-1_on_azure_linux_3.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| squid-cache | squid | < 6.4 | 6.4 |
| squid | squid | >= 0 < 4.13-10+deb11u5 | 4.13-10+deb11u5 |
| squid | squid | >= 0 < 5.7-2+deb12u3 | 5.7-2+deb12u3 |
| squid | squid | >= 0 < 6.5-1 | 6.5-1 |
| squid | squid | >= 0 < 6.5-1 | 6.5-1 |
| squid | squid | >= 0 < 4.10-1ubuntu1.11 | 4.10-1ubuntu1.11 |
| squid | squid | >= 0 < 4.10-1ubuntu1.12 | 4.10-1ubuntu1.12 |
| squid | squid | >= 0 < 4.10-1ubuntu1.10 | 4.10-1ubuntu1.10 |
| squid | squid | >= 0 < 5.7-0ubuntu0.22.04.4 | 5.7-0ubuntu0.22.04.4 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_ubuntu8.6HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Squid vulnerability
vendor_ubuntu·2024-04-23·CVSS 8.6
CVE-2023-49288 [HIGH] Squid vulnerability
Title: Squid vulnerability
Summary: Squid could be made to crash if it received specially crafted network
traffic.
USN-6728-1 fixed vulnerabilities in Squid. The fix for CVE-2023-5824 caused
Squid to crash in certain environments on Ubuntu 20.04 LTS and was disabled
in USN-6728-2. The problematic fix for CVE-2023-5824 has now been corrected
and reinstated in this update.
We apologize for the inconvenience.
Original advisory details:
Joshua Rogers discovered that Squid incorrectly handled collapsed
forwarding. A remote attacker could possibly use this issue to cause Squid
to crash, resulting in a denial of service. This issue only affected Ubuntu
20.04 LTS and Ubuntu 22.04 LTS. (CVE-2023-49288)
Joshua Rogers discovered that Squid incorrectly handled certain structural
elements. A remo
Ubuntu
Squid regression
vendor_ubuntu·2024-04-11·CVSS 8.6
CVE-2023-5824 [HIGH] Squid regression
Title: Squid regression
Summary: USN-6728-1 introduced a regression in Squid.
USN-6728-1 fixed vulnerabilities in Squid. The fix for CVE-2023-5824 caused
Squid to crash in certain environments on Ubuntu 20.04 LTS. The problematic
fix has been reverted pending further investigation.
We apologize for the inconvenience.
Original advisory details:
Joshua Rogers discovered that Squid incorrectly handled collapsed
forwarding. A remote attacker could possibly use this issue to cause Squid
to crash, resulting in a denial of service. This issue only affected Ubuntu
20.04 LTS and Ubuntu 22.04 LTS. (CVE-2023-49288)
Joshua Rogers discovered that Squid incorrectly handled certain structural
elements. A remote attacker could possibly use this issue to cause Squid to
crash, resulting in a denial of
Ubuntu
Squid vulnerabilities
vendor_ubuntu·2024-04-10·CVSS 8.6
CVE-2024-23638 [HIGH] Squid vulnerabilities
Title: Squid vulnerabilities
Summary: Several security issues were fixed in Squid.
Joshua Rogers discovered that Squid incorrectly handled collapsed
forwarding. A remote attacker could possibly use this issue to cause Squid
to crash, resulting in a denial of service. This issue only affected Ubuntu
20.04 LTS and Ubuntu 22.04 LTS. (CVE-2023-49288)
Joshua Rogers discovered that Squid incorrectly handled certain structural
elements. A remote attacker could possibly use this issue to cause Squid to
crash, resulting in a denial of service. (CVE-2023-5824)
Joshua Rogers discovered that Squid incorrectly handled Cache Manager error
responses. A remote trusted client can possibly use this issue to cause
Squid to crash, resulting in a denial of service. (CVE-2024-23638)
Joshua Rogers discovere
Microsoft
Squid: dos against http and https
vendor_msrc·2023-11-14·CVSS 7.5
CVE-2023-5824 [HIGH] CWE-755 Squid: dos against http and https
Squid: dos against http and https
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us
Red Hat
squid: DoS against HTTP and HTTPS
vendor_redhat·2023-10-19·CVSS 7.5
CVE-2023-5824 [HIGH] CWE-755 squid: DoS against HTTP and HTTPS
squid: DoS against HTTP and HTTPS
A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the worker process when a large header is retrieved from the disk cache, resulting in a denial of service.
A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the worker process when a large header is retrieved from the disk cache, resulting in a denial of service.
Statement: This vulnerability only affects configurations with the `cache_dir` direct
Debian
CVE-2023-5824: squid - A flaw was found in Squid. The limits applied for validation of HTTP response he...
vendor_debian·2023·CVSS 7.5
CVE-2023-5824 [HIGH] CVE-2023-5824: squid - A flaw was found in Squid. The limits applied for validation of HTTP response he...
A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the worker process when a large header is retrieved from the disk cache, resulting in a denial of service.
Scope: local
bookworm: resolved (fixed in 5.7-2+deb12u3)
bullseye: resolved (fixed in 4.13-10+deb11u5)
forky: resolved (fixed in 6.5-1)
sid: resolved (fixed in 6.5-1)
trixie: resolved (fixed in 6.5-1)
OSV
squid vulnerability
osv·2024-04-23·CVSS 7.5
CVE-2023-5824 [HIGH] squid vulnerability
squid vulnerability
USN-6728-1 fixed vulnerabilities in Squid. The fix for CVE-2023-5824 caused
Squid to crash in certain environments on Ubuntu 20.04 LTS and was disabled
in USN-6728-2. The problematic fix for CVE-2023-5824 has now been corrected
and reinstated in this update.
We apologize for the inconvenience.
Original advisory details:
Joshua Rogers discovered that Squid incorrectly handled collapsed
forwarding. A remote attacker could possibly use this issue to cause Squid
to crash, resulting in a denial of service. This issue only affected Ubuntu
20.04 LTS and Ubuntu 22.04 LTS. (CVE-2023-49288)
Joshua Rogers discovered that Squid incorrectly handled certain structural
elements. A remote attacker could possibly use this issue to cause Squid to
crash, resulting in a denial of serv
OSV
squid regression
osv·2024-04-11·CVSS 7.5
CVE-2023-5824 [HIGH] squid regression
squid regression
USN-6728-1 fixed vulnerabilities in Squid. The fix for CVE-2023-5824 caused
Squid to crash in certain environments on Ubuntu 20.04 LTS. The problematic
fix has been reverted pending further investigation.
We apologize for the inconvenience.
Original advisory details:
Joshua Rogers discovered that Squid incorrectly handled collapsed
forwarding. A remote attacker could possibly use this issue to cause Squid
to crash, resulting in a denial of service. This issue only affected Ubuntu
20.04 LTS and Ubuntu 22.04 LTS. (CVE-2023-49288)
Joshua Rogers discovered that Squid incorrectly handled certain structural
elements. A remote attacker could possibly use this issue to cause Squid to
crash, resulting in a denial of service. (CVE-2023-5824)
Joshua Rogers discovered that Squid
OSV
squid vulnerabilities
osv·2024-04-10·CVSS 7.5
CVE-2023-49288 [HIGH] squid vulnerabilities
squid vulnerabilities
Joshua Rogers discovered that Squid incorrectly handled collapsed
forwarding. A remote attacker could possibly use this issue to cause Squid
to crash, resulting in a denial of service. This issue only affected Ubuntu
20.04 LTS and Ubuntu 22.04 LTS. (CVE-2023-49288)
Joshua Rogers discovered that Squid incorrectly handled certain structural
elements. A remote attacker could possibly use this issue to cause Squid to
crash, resulting in a denial of service. (CVE-2023-5824)
Joshua Rogers discovered that Squid incorrectly handled Cache Manager error
responses. A remote trusted client can possibly use this issue to cause
Squid to crash, resulting in a denial of service. (CVE-2024-23638)
Joshua Rogers discovered that Squid incorrectly handled the HTTP Chunked
decoder. A r
OSV
CVE-2023-5824: A flaw was found in Squid
osv·2023-11-03·CVSS 7.5
CVE-2023-5824 [HIGH] CVE-2023-5824: A flaw was found in Squid
A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the worker process when a large header is retrieved from the disk cache, resulting in a denial of service.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:7465https://access.redhat.com/errata/RHSA-2023:7668https://access.redhat.com/errata/RHSA-2024:0072https://access.redhat.com/errata/RHSA-2024:0397https://access.redhat.com/errata/RHSA-2024:0771https://access.redhat.com/errata/RHSA-2024:0772https://access.redhat.com/errata/RHSA-2024:0773https://access.redhat.com/errata/RHSA-2024:1153https://access.redhat.com/security/cve/CVE-2023-5824https://bugzilla.redhat.com/show_bug.cgi?id=2245914https://github.com/squid-cache/squid/security/advisories/GHSA-543m-w2m2-g255https://access.redhat.com/errata/RHSA-2023:7465https://access.redhat.com/errata/RHSA-2023:7668https://access.redhat.com/errata/RHSA-2024:0072https://access.redhat.com/errata/RHSA-2024:0397https://access.redhat.com/errata/RHSA-2024:0771https://access.redhat.com/errata/RHSA-2024:0772https://access.redhat.com/errata/RHSA-2024:0773https://access.redhat.com/errata/RHSA-2024:1153https://access.redhat.com/security/cve/CVE-2023-5824https://bugzilla.redhat.com/show_bug.cgi?id=2245914https://github.com/squid-cache/squid/security/advisories/GHSA-543m-w2m2-g255https://lists.debian.org/debian-lts-announce/2025/09/msg00027.htmlhttps://security.netapp.com/advisory/ntap-20231130-0003/
2023-11-03
Published