Lucene search

K
cloudlinuxCloudLinuxCLSA-2023:1703183242
HistoryDec 21, 2023 - 6:27 p.m.

squid34: Fix of 2 CVEs

2023-12-2118:27:26
repo.cloudlinux.com
20
squid34
unix
date parsing
rfc 1123
buffer overread
dos attack
helper process management

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

AI Score

7.3

Confidence

Low

EPSS

0.019

Percentile

88.7%

  • CVE-2023-49285: Fix date parsing in RFC 1123 to prevent Buffer OverRead
  • CVE-2023-49286: Fix DoS attack against Helper process management
OSVersionArchitecturePackageVersionFilename
Centos6x86_64squid34< 3.4.14squid34-3.4.14-16.el6.tuxcare.els6.src.rpm

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

AI Score

7.3

Confidence

Low

EPSS

0.019

Percentile

88.7%