CVE-2023-46847
גבוהה 7.5
תיאור (מקור, אנגלית)
Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - EPSS — סבירות ניצול
- 88% (אחוזון 100) נכון ל-8/10/2026
- CWE
- CWE-120
מוצרים מושפעים
squid-cache: squid; redhat: enterprise linux; redhat: enterprise linux eus; redhat: enterprise linux for arm 64; redhat: enterprise linux for ibm z systems; redhat: enterprise linux for power little endian; redhat: enterprise linux server; redhat: enterprise linux server aus; redhat: enterprise linux server tus; redhat: enterprise linux workstation
קישורים
- https://github.com/squid-cache/squid/security/advisories/GHSA-phqj-m8gv-cq4g Vendor Advisory
- https://github.com/squid-cache/squid/security/advisories/GHSA-phqj-m8gv-cq4g Vendor Advisory
- https://access.redhat.com/errata/RHSA-2023:6266 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:6267 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:6268 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:6748 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:6801 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:6803 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:6804 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2023:6805 Third Party Advisory