PT-2023-7040 · Squid+8 · Squid+9

Joshua Rogers

·

Published

2023-10-19

·

Updated

2026-03-29

·

CVE-2023-46848

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Squid (affected versions not specified)
Description The issue allows a remote attacker to perform a Denial of Service by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs from FTP Native input. This can lead to a disruption in service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:6266
ALSA-2023:6748
ALT-PU-2023-7250
ALT-PU-2023-7254
ALT-PU-2023-7461
AZL-31903
BDU:2023-08062
CVE-2023-46848
DSA-5637-1
GHSA-2G3C-PG7Q-G59W
MGASA-2023-0315
OPENSUSE-SU-2023_4380-1
OPENSUSE-SU-2024:13398-1
RHSA-2023:6266
RHSA-2023:6268
RHSA-2023:6748
RHSA-2023_6266
RHSA-2023_6748
RLSA-2023:6266
ROSA-SA-2024-2477
SUSE-SU-2023:4380-1
SUSE-SU-2023:4381-1
SUSE-SU-2023:4384-1
USN-6500-1

Affected Products

Alt Linux
Almalinux
Linuxmint
Red Hat
Red Os
Rocky Linux
Squid
Squid Cache
Suse
Ubuntu