Lucene search

K
mageiaGentoo FoundationMGASA-2023-0315
HistoryNov 10, 2023 - 2:37 a.m.

Updated squid packages fix security vulnerabilities

2023-11-1002:37:11
Gentoo Foundation
advisories.mageia.org
48
squid
security vulnerabilities
http/1.1
icap
cve-2023-46846
denial of service
http digest authentication
cve-2023-46847
ftp
cve-2023-46848

CVSS3

9.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N

AI Score

7.4

Confidence

Low

EPSS

0.03

Percentile

91.1%

The updated packages fix security vulnerabilities: Request/Response smuggling in HTTP/1.1 and ICAP. (CVE-2023-46846) Denial of Service in HTTP Digest Authentication. (CVE-2023-46847) Denial of Service in FTP. (CVE-2023-46848)

OSVersionArchitecturePackageVersionFilename
Mageia9noarchsquid< 5.9-1.1squid-5.9-1.1.mga9

CVSS3

9.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N

AI Score

7.4

Confidence

Low

EPSS

0.03

Percentile

91.1%