CVE-2023-46847: Squid: denial of service in http digest authentication
Description: Due to a buffer overflow bug Squid is vulnerable to a Denial of Service attack against HTTP Digest Authentication
Reference: https://github.com/squid-cache/squid/security/advisories/GHSA-phqj-m8gv-cq4g
Affected versions: 3.2.0.1-5.9, 6.0-6.3
Other sources
Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.
— Debian
Squid: denial of service in http digest authentication
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/squidto a version that resolves this vulnerability.Fixed in 6.4 - Upgrade
Upgrade
ubuntu/squidto a version that resolves this vulnerability.Fixed in 4.10-1ubuntu1.8 - Upgrade
Upgrade
ubuntu/squidto a version that resolves this vulnerability.Fixed in 5.7-0ubuntu0.22.04.2 - Upgrade
Upgrade
ubuntu/squidto a version that resolves this vulnerability.Fixed in 5.7-1ubuntu3.1 - Upgrade
Upgrade
ubuntu/squidto a version that resolves this vulnerability.Fixed in 6.1-2ubuntu1.1 - Upgrade
Upgrade
ubuntu/squidto a version that resolves this vulnerability.Fixed in 6.4 - Upgrade
Upgrade
ubuntu/squid3to a version that resolves this vulnerability.Fixed in 3.5.27-1ubuntu1.14+ - Upgrade
Upgrade
ubuntu/squid3to a version that resolves this vulnerability.Fixed in 3.5.12-1ubuntu7.16+ - Upgrade
Upgrade
debian/squidto a version that resolves this vulnerability.Fixed in 4.6-1+deb10u10Fixed in 4.13-10+deb11u3Fixed in 5.7-2+deb12u1Fixed in 6.9-1
Event History
Frequently Asked Questions
What is CVE-2023-46847?
CVE-2023-46847 is a vulnerability in Squid that allows a remote attacker to perform a denial of service attack through a buffer overflow in HTTP Digest Authentication.
How severe is CVE-2023-46847?
CVE-2023-46847 has a severity rating of 9.9, which is classified as critical.
Which software versions are affected by CVE-2023-46847?
The affected software versions include Squid up to version 6.4 and Squid-Cache versions 3.2.0.1 to 6.4.
How can I mitigate CVE-2023-46847?
To mitigate CVE-2023-46847, update Squid to version 6.4 or apply the recommended patches provided by the vendor.
Where can I find more information about CVE-2023-46847?
You can find more information about CVE-2023-46847 in the references: [GitHub Advisory](https://github.com/squid-cache/squid/security/advisories/GHSA-phqj-m8gv-cq4g), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2245917), and [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2023:6266).