PT-2018-9215 · Squid+5 · Squid Http Caching Proxy+6
Louis Dion-Marcil
·
Publicado
2018-01-29
·
Atualizado
2024-06-15
·
CVE-2018-1000024
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Squid HTTP Caching Proxy versions 3.0 through 3.5.27
Squid HTTP Caching Proxy versions 4.0 through 4.0.22
Description:
The issue is related to Incorrect Pointer Handling in ESI Response Processing, which can cause Denial of Service for all clients using the proxy. This can be exploited when a remote server delivers an HTTP response payload containing valid but unusual ESI syntax.
Recommendations:
For Squid HTTP Caching Proxy versions 3.0 through 3.5.27, update to version 4.0.23 or later.
For Squid HTTP Caching Proxy versions 4.0 through 4.0.22, update to version 4.0.23 or later.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Red Hat
Squid Cache
Squid Http Caching Proxy
Suse
Ubuntu