PT-2018-9215 · Squid+5 · Squid Http Caching Proxy+6

Louis Dion-Marcil

·

Publicado

2018-01-29

·

Atualizado

2024-06-15

·

CVE-2018-1000024

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Squid HTTP Caching Proxy versions 3.0 through 3.5.27 Squid HTTP Caching Proxy versions 4.0 through 4.0.22
Description: The issue is related to Incorrect Pointer Handling in ESI Response Processing, which can cause Denial of Service for all clients using the proxy. This can be exploited when a remote server delivers an HTTP response payload containing valid but unusual ESI syntax.
Recommendations: For Squid HTTP Caching Proxy versions 3.0 through 3.5.27, update to version 4.0.23 or later. For Squid HTTP Caching Proxy versions 4.0 through 4.0.22, update to version 4.0.23 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

ALT-PU-2018-2314
CESA-2020_1068
CVE-2018-1000024
DLA-1266-1
DSA-4122-1
OPENSUSE-SU-2024:11403-1
RHSA-2020:1068
RHSA-2020_1068
SUSE-SU-2018:0636-1
SUSE-SU-2018:0752-1
SUSE-SU-2018_0636-1
SUSE-SU-2018_0752-1
USN-3557-1
USN-4059-2

Produtos afetados

Alt Linux
Centos
Red Hat
Squid Cache
Squid Http Caching Proxy
Suse
Ubuntu