CVE-2023-46848: Squid: denial of service in ftp
Description: a) Due to an Incorrect Conversion between Numeric Types bug Squid is vulnerable to a Denial of Service attack against FTP Native Relay input validation.
b) Due to an Incorrect Conversion between Numeric Types bug Squid is vulnerable to a Denial of Service attack against ftp:// URL validation and access control.
Reference: https://github.com/squid-cache/squid/security/advisories/GHSA-2g3c-pg7q-g59w
Affected versions: 5.0.3-5.9, 6.0-6.3
Other sources
Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs from FTP Native input.
— Debian
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-46848?
CVE-2023-46848 is a vulnerability that allows for a Denial of Service attack in Squid, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs from FTP Native input.
How severe is CVE-2023-46848?
CVE-2023-46848 has a severity rating of 8.6 out of 10, which is considered high.
What is the affected software for CVE-2023-46848?
The affected software for CVE-2023-46848 includes Squid version 6.4, Squid-Cache Squid versions between 5.0.3 and 6.4, and Redhat Enterprise Linux versions 9.0, 9.2, and EUS 9.2.
How can the vulnerability in CVE-2023-46848 be exploited?
The vulnerability in CVE-2023-46848 can be exploited by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs from FTP Native input.
Are there any fixes or remedies available for CVE-2023-46848?
Yes, fixes and remedies for CVE-2023-46848 are available. Please refer to the provided Red Hat Security Advisories for more information.