CVE-2018-1000027
Description
The Squid Software Foundation Squid HTTP Caching Proxy version prior to version 4.0.23 contains a NULL Pointer Dereference vulnerability in HTTP Response X-Forwarded-For header processing that can result in Denial of Service to all clients of the proxy. This attack appear to be exploitable via Remote HTTP server responding with an X-Forwarded-For header to certain types of HTTP request. This vulnerability appears to have been fixed in 4.0.23 and later.
Risk Information
Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
68.081
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| squid3 security update(DSA-4122-1) squid3_3.4.8-6+deb8u5_amd64.deb | Linux |
| squid3 security update(DSA-4122-1) squid3_3.5.23-5+deb9u1_all.deb | Linux |
| SUSE-SU-2018:0636-1(SUSE Linux Enterprise Server 12-SP2 ) squid-3.5.21-26.6.1.x86_64.rpm | Linux |
| SUSE-SU-2018:0636-1(SUSE Linux Enterprise Server 12-SP2 ) squid-debuginfo-3.5.21-26.6.1.x86_64.rpm | Linux |
| SUSE-SU-2018:0636-1(SUSE Linux Enterprise Server 12-SP2 ) squid-debugsource-3.5.21-26.6.1.x86_64.rpm | Linux |
| (RHSA-2020:1068) squid security and bug fix update squid-3.5.20-15.el7.x86_64.rpm | Linux |
| (RHSA-2020:1068) squid security and bug fix update squid-migration-script-3.5.20-15.el7.x86_64.rpm | Linux |
| (RHSA-2020:1068) squid security and bug fix update squid-sysvinit-3.5.20-15.el7.x86_64.rpm | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234