https://seclists.org/oss-sec/2023/q4/96: Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
Published Oct 13, 2023
·Updated
Affected Software
1 affected component
Squid Squid Proxy
Frequently Asked Questions
1
What is the severity of GHSA-543m-w2m2-g255?
GHSA-543m-w2m2-g255 is considered a high severity vulnerability due to its potential for cache poisoning and XSS.
2
How do I fix GHSA-543m-w2m2-g255?
To fix GHSA-543m-w2m2-g255, update to the latest version of Squid Proxy where the vulnerability has been patched.
3
What does CVE-2021-46784 entail?
CVE-2021-46784 involves a vulnerability related to assertion failures in Gopher response handling in Squid.
4
What is the impact of CVE-2021-46784?
The impact of CVE-2021-46784 may lead to application crashes and denial of service in Squid Proxy servers.
5
Is there a known exploit for GHSA-543m-w2m2-g255?
Yes, GHSA-543m-w2m2-g255 has publicly disclosed exploitation scenarios, primarily exploiting large stored response headers.