Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia: 2024-0102 Critical: Squid Denial of Service Attacks

mageia
Calendar Grey March 31, 2024
Dist Mageia Esm H88
Recent updates to Squid packages have addressed several security vulnerabilities that may impact Mageia systems. It's essential to review the listed CVEs for possible risks
Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service ...

Summary

Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. (CVE-2023-46724) Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. (CVE-2023-49285) Due to an Incorrect Check of Function Return Value bug Squid is vulnerable to a Denial of Service attack against its Helper process management. (CVE-2023-49286) Due to an Uncontrolled Recursion bug in versions 2.6 through 2.7.STABLE9, versions 3.1 through 5.9, and versions 6.0.1 through 6.5, Squid may be vulnerable to a Denial of Service attack against HTTP Request parsing. This problem...

References

- https://bugs.mageia.org/show_bug.cgi?id=33003

-

- https://lists.debian.org/debian-security-announce/2024/msg00043.html

- https://www.cve.org/CVERecord?id=CVE-2023-46724

- https://www.cve.org/CVERecord?id=CVE-2023-49285

- https://www.cve.org/CVERecord?id=CVE-2023-49286

- https://www.cve.org/CVERecord?id=CVE-2023-50269

- https://www.cve.org/CVERecord?id=CVE-2024-23638

- https://www.cve.org/CVERecord?id=CVE-2024-25111

- https://www.cve.org/CVERecord?id=CVE-2024-25617

Resolution

SRPMS

- 9/core/squid-5.9-1.2.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 31 Mar 2024
URL: https://advisories.mageia.org/MGASA-2024-0102.html
Type: security
CVE: CVE-2023-46724, CVE-2023-49285, CVE-2023-49286, CVE-2023-50269, CVE-2024-23638, CVE-2024-25111, CVE-2024-25617

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here