Lucene search

K
redosRedosROS-20231115-01
HistoryNov 15, 2023 - 12:00 a.m.

ROS-20231115-01

2023-11-1500:00:00
redos.red-soft.ru
19
squid proxy
vulnerabilities
buffer overflow
header validation
chunked decoder
ftp urls
denial of service
http
authentication
memory heap
fragmented encoding syntax
remote exploitation
ftp urls from ftp native input data
unix

CVSS3

9.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N

AI Score

7.7

Confidence

High

EPSS

0.03

Percentile

91.1%

A vulnerability in the Squid proxy server related to the execution of a “buffer overflow” attack, writing up to 2MB of
of arbitrary data to the memory heap when Squid is configured to accept HTTP Digest Authentication.
Exploitation of the vulnerability could allow an attacker acting remotely to cause a denial of service

Squid proxy vulnerability related to restrictions applied to the header validation of the
HTTP response headers before caching. Exploitation of the vulnerability could allow an attacker acting remotely to cause a denial of service.
remotely to cause a denial of service

Squid proxy server chunked decoder vulnerability related to the server’s interpretation of fragmented syntax.
fragmented encoding syntax. Exploitation of the vulnerability could allow an attacker,
acting remotely to communicate directly with the server.

Squid proxy vulnerability related to sending ftp URLs in HTTP request messages, or
creating ftp URLs from FTP Native input data. Exploitation of the vulnerability could allow
an attacker acting remotely to cause a denial of service

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64squid< 6.5-1UNKNOWN

CVSS3

9.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N

AI Score

7.7

Confidence

High

EPSS

0.03

Percentile

91.1%