Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-49286
HistoryDec 04, 2023 - 12:00 a.m.

CVE-2023-49286

2023-12-0400:00:00
ubuntu.com
ubuntu.com
16
squid
caching proxy
vulnerability
version 6.5
dos attack
helper process
upgrade
unix

8.6 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

6.9 Medium

AI Score

Confidence

High

0.019 Low

EPSS

Percentile

88.8%

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more.
Due to an Incorrect Check of Function Return Value bug Squid is vulnerable
to a Denial of Service attack against its Helper process management. This
bug is fixed by Squid version 6.5. Users are advised to upgrade. There are
no known workarounds for this vulnerability.

OSVersionArchitecturePackageVersionFilename
ubuntu20.04noarchsquid< 4.10-1ubuntu1.9UNKNOWN
ubuntu22.04noarchsquid< 5.7-0ubuntu0.22.04.3UNKNOWN
ubuntu23.04noarchsquid< 5.7-1ubuntu3.2UNKNOWN
ubuntu23.10noarchsquid< 6.1-2ubuntu1.2UNKNOWN
ubuntu24.04noarchsquid< 6.5-1ubuntu1UNKNOWN
ubuntu18.04noarchsquid3< 3.5.27-1ubuntu1.14+esm2UNKNOWN
ubuntu16.04noarchsquid3< 3.5.12-1ubuntu7.16+esm3UNKNOWN

8.6 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

6.9 Medium

AI Score

Confidence

High

0.019 Low

EPSS

Percentile

88.8%