Lucene search

K
oraclelinuxOracleLinuxELSA-2024-1376
HistoryMar 20, 2024 - 12:00 a.m.

squid security update

2024-03-2000:00:00
linux.oracle.com
16
squid security update
version 6.8
denial of service
http request parsing
http chunked decoding
cve-2023-50269
cve-2024-25111
cve-2024-25617

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

AI Score

6.9

Confidence

Low

EPSS

0.005

Percentile

75.3%

[7:5.5-6.0.1.8]

  • Rebuild with release bump
    [7:5.5-6.8]
  • Resolves: RHEL-19555 - squid: denial of service in HTTP request
    parsing (CVE-2023-50269)
    [7:5.5-6.7]
  • Resolves: RHEL-28614 - squid: Denial of Service in HTTP Chunked
    Decoding (CVE-2024-25111)
    [7:5.5-6.6]
  • Resolves: RHEL-26091 - squid: denial of service in HTTP header
    parser (CVE-2024-25617)

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

AI Score

6.9

Confidence

Low

EPSS

0.005

Percentile

75.3%