https://seclists.org/oss-sec/2023/q4/96: Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.

Published Oct 13, 2023
·
Updated

Affected Software

1 affected component
Squid Squid Proxy

Frequently Asked Questions

1

What is the severity of GHSA-543m-w2m2-g255?

GHSA-543m-w2m2-g255 is considered a high severity vulnerability due to its potential for cache poisoning and XSS.

2

How do I fix GHSA-543m-w2m2-g255?

To fix GHSA-543m-w2m2-g255, update to the latest version of Squid Proxy where the vulnerability has been patched.

3

What does CVE-2021-46784 entail?

CVE-2021-46784 involves a vulnerability related to assertion failures in Gopher response handling in Squid.

4

What is the impact of CVE-2021-46784?

The impact of CVE-2021-46784 may lead to application crashes and denial of service in Squid Proxy servers.

5

Is there a known exploit for GHSA-543m-w2m2-g255?

Yes, GHSA-543m-w2m2-g255 has publicly disclosed exploitation scenarios, primarily exploiting large stored response headers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203