First published: Tue Oct 24 2023(Updated: )
Description: a) Due to an Incorrect Conversion between Numeric Types bug Squid is vulnerable to a Denial of Service attack against FTP Native Relay input validation. b) Due to an Incorrect Conversion between Numeric Types bug Squid is vulnerable to a Denial of Service attack against ftp:// URL validation and access control. Reference: <a href="https://github.com/squid-cache/squid/security/advisories/GHSA-2g3c-pg7q-g59w">https://github.com/squid-cache/squid/security/advisories/GHSA-2g3c-pg7q-g59w</a> Affected versions: 5.0.3-5.9, 6.0-6.3
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Squid-Cache Squid | >=5.0.3<6.4 | |
Redhat Enterprise Linux | =9.0 | |
Redhat Enterprise Linux Eus | =9.2 | |
Redhat Enterprise Linux Server Aus | =9.2 | |
Redhat Enterprise Linux Server Tus | =9.2 | |
redhat/squid | <6.4 | 6.4 |
ubuntu/squid | <5.7-0ubuntu0.22.04.2 | 5.7-0ubuntu0.22.04.2 |
ubuntu/squid | <5.7-1ubuntu3.1 | 5.7-1ubuntu3.1 |
ubuntu/squid | <6.1-2ubuntu1.1 | 6.1-2ubuntu1.1 |
ubuntu/squid | <6.4 | 6.4 |
debian/squid | <=5.7-2 | 4.6-1+deb10u7 4.6-1+deb10u10 4.13-10+deb11u2 4.13-10+deb11u3 5.7-2+deb12u1 6.9-1 |
>=5.0.3<6.4 | ||
=9.0 | ||
=9.2 | ||
=9.2 | ||
=9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-46848 is a vulnerability that allows for a Denial of Service attack in Squid, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs from FTP Native input.
CVE-2023-46848 has a severity rating of 8.6 out of 10, which is considered high.
The affected software for CVE-2023-46848 includes Squid version 6.4, Squid-Cache Squid versions between 5.0.3 and 6.4, and Redhat Enterprise Linux versions 9.0, 9.2, and EUS 9.2.
The vulnerability in CVE-2023-46848 can be exploited by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs from FTP Native input.
Yes, fixes and remedies for CVE-2023-46848 are available. Please refer to the provided Red Hat Security Advisories for more information.