CVE-2023-46728

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of Service attack against Squid's Gopher gateway. The gopher protocol is always available and enabled in Squid prior to Squid 6.0.1. Responses triggering this bug are possible to be received from any gopher server, even those without malicious intent. Gopher support has been removed in Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should reject all gopher URL requests.
Configurations

Configuration 1 (hide)

cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:*

History

29 Dec 2023, 03:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/A5QASTMCUSUEW3UOMKHZJB3FTONWSRXS/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MEV66D3PAAY6K7TWDT3WZBLCPLASFJDC/ -

14 Dec 2023, 10:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20231214-0006/ -

14 Nov 2023, 20:00

Type Values Removed Values Added
First Time Squid-cache
Squid-cache squid
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:*
References (MISC) https://github.com/squid-cache/squid/commit/6ea12e8fb590ac6959e9356a81aa3370576568c3 - (MISC) https://github.com/squid-cache/squid/commit/6ea12e8fb590ac6959e9356a81aa3370576568c3 - Patch
References (MISC) https://github.com/squid-cache/squid/security/advisories/GHSA-cg5h-v6vc-w33f - (MISC) https://github.com/squid-cache/squid/security/advisories/GHSA-cg5h-v6vc-w33f - Vendor Advisory

06 Nov 2023, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-06 18:15

Updated : 2023-12-29 03:15


NVD link : CVE-2023-46728

Mitre link : CVE-2023-46728

CVE.ORG link : CVE-2023-46728


JSON object : View

Products Affected

squid-cache

  • squid
CWE
CWE-476

NULL Pointer Dereference