Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!Close

CVE-2023-46724

Published: 1 November 2023

Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This bug is fixed in Squid version 6.4. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. Those who you use a prepackaged version of Squid should refer to the package vendor for availability information on updated packages.

Notes

AuthorNote
mdeslaur
only affects builds with openssl, which is not enabled in
focal and earlier

Priority

Medium

Cvss 3 Severity Score

7.5

Score breakdown

Status

Package Release Status
squid
Launchpad, Ubuntu, Debian
trusty Ignored
(end of standard support)
xenial Ignored
(end of standard support)
bionic Ignored
(end of standard support)
focal Not vulnerable
(code not compiled)
jammy
Released (5.7-0ubuntu0.22.04.2)
lunar
Released (5.7-1ubuntu3.1)
mantic
Released (6.1-2ubuntu1.1)
upstream Needs triage

Patches:
upstream: https://github.com/squid-cache/squid/commit/b70f864940225dfe69f9f653f948e787f99c3810 (master)
upstream: https://github.com/squid-cache/squid/commit/12b8efc07ff74548d5582c4890f8bdb9057a1bb3 (v6)
upstream: https://github.com/squid-cache/squid/commit/792ef23e6e1c05780fe17f733859eef6eb8c8be3 (v5)
squid3
Launchpad, Ubuntu, Debian
trusty Ignored
(end of standard support)
xenial Needs triage

bionic Needs triage

focal Does not exist

jammy Does not exist

lunar Does not exist

mantic Does not exist

upstream Needs triage

Severity score breakdown

Parameter Value
Base score 7.5
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality None
Integrity impact None
Availability impact High
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H