CVE-2018-1000024

Description

The Squid Software Foundation Squid HTTP Caching Proxy version 3.0 to 3.5.27, 4.0 to 4.0.22 contains a Incorrect Pointer Handling vulnerability in ESI Response Processing that can result in Denial of Service for all clients using the proxy.. This attack appear to be exploitable via Remote server delivers an HTTP response payload containing valid but unusual ESI syntax.. This vulnerability appears to have been fixed in 4.0.23 and later.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
11.511

Associated Vulnerability

VulnerabilityOS Platform
Web proxy cache server (USN-3557-1) squid3_3.3.8-1ubuntu6.11_i386.debLinux
Web proxy cache server (USN-3557-1) squid3_3.3.8-1ubuntu6.11_amd64.debLinux
Web proxy cache server (USN-3557-1) squid3_3.5.12-1ubuntu7.5_all.debLinux
Web proxy cache server (USN-3557-1) squid3_3.5.23-5ubuntu1.1_all.debLinux
squid3 security update(DSA-4122-1) squid3_3.4.8-6+deb8u5_amd64.debLinux
squid3 security update(DSA-4122-1) squid3_3.5.23-5+deb9u1_all.debLinux
SUSE-SU-2018:0636-1(SUSE Linux Enterprise Server 12-SP2 ) squid-3.5.21-26.6.1.x86_64.rpmLinux
SUSE-SU-2018:0636-1(SUSE Linux Enterprise Server 12-SP2 ) squid-debuginfo-3.5.21-26.6.1.x86_64.rpmLinux
SUSE-SU-2018:0636-1(SUSE Linux Enterprise Server 12-SP2 ) squid-debugsource-3.5.21-26.6.1.x86_64.rpmLinux
(RHSA-2020:1068) squid security and bug fix update squid-3.5.20-15.el7.x86_64.rpmLinux
(RHSA-2020:1068) squid security and bug fix update squid-migration-script-3.5.20-15.el7.x86_64.rpmLinux
(RHSA-2020:1068) squid security and bug fix update squid-sysvinit-3.5.20-15.el7.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234