CVE-2020-24606

Description

Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only occurs when cache_peer is used with the cache digests feature. The problem exists because peerDigestHandleReply() livelocking in peer_digest.cc mishandles EOF.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
6.342

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Security Guardium 10.5Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 10.6Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.1Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.2Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.3Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.0Windows
squid security update(DSA-4751-1) squid_4.6-1+deb10u4_i386.debLinux
squid security update(DSA-4751-1) squid_4.6-1+deb10u4_amd64.debLinux
Web proxy cache server (USN-4477-1) squid_4.10-1ubuntu1.2_amd64.debLinux
Web proxy cache server (USN-4551-1) squid_3.5.27-1ubuntu1.9_i386.debLinux
Web proxy cache server (USN-4551-1) squid_3.5.27-1ubuntu1.9_amd64.debLinux
Web proxy cache server (USN-4551-1) squid_3.5.12-1ubuntu7.15_i386.debLinux
Web proxy cache server (USN-4551-1) squid_3.5.12-1ubuntu7.15_amd64.debLinux
(RHSA-2020:4082) squid security update squid-3.5.20-17.el7_9.4.x86_64.rpmLinux
(RHSA-2020:4082) squid security update squid-migration-script-3.5.20-17.el7_9.4.x86_64.rpmLinux
(RHSA-2020:4082) squid security update squid-sysvinit-3.5.20-17.el7_9.4.x86_64.rpmLinux
(RHSA-2020:4743) squid:4 security, bug fix, and enhancement update squid-4.11-3.module+el8.3.0+7851+7808b5f9.x86_64.rpmLinux
(RHSA-2020:4743) squid:4 security, bug fix, and enhancement update squid-debugsource-4.11-3.module+el8.3.0+7851+7808b5f9.x86_64.rpmLinux
Squid update (ELSA-2020-4082) squid-3.5.20-17.el7_9.4.x86_64.rpmLinux
Squid-migration-script update (ELSA-2020-4082) squid-migration-script-3.5.20-17.el7_9.4.x86_64.rpmLinux
Squid-sysvinit update (ELSA-2020-4082) squid-sysvinit-3.5.20-17.el7_9.4.x86_64.rpmLinux
(CESA-2020:4082) squid security update squid-3.5.20-17.el7_9.4.x86_64.rpmLinux
(CESA-2020:4082) squid security update squid-migration-script-3.5.20-17.el7_9.4.x86_64.rpmLinux
(CESA-2020:4082) squid security update squid-sysvinit-3.5.20-17.el7_9.4.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234