Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.144458
Kategorie:Denial of Service
Titel:Squid Security Update Advisory SQUID-2020:9
Zusammenfassung:Squid is prone to a denial of service vulnerability when processing Cache; Digest responses.
Beschreibung:Summary:
Squid is prone to a denial of service vulnerability when processing Cache
Digest responses.

Vulnerability Insight:
Due to Improper Input Validation Squid is vulnerable to a denial of service
attack against the machine operating Squid.

Vulnerability Impact:
This problem allows a trusted peer to perform a Denial of Service by
consuming all available CPU cycles on the machine running Squid when handling a crafted Cache Digest response
message.

This attack is limited to Squid using cache_peer with cache digests feature.

Affected Software/OS:
Squid versions 3.0 - 4.12 and 5.0.1 - 5.0.3.

Solution:
Update to version 4.13, 5.0.4 or later.

CVSS Score:
7.1

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2020-24606
Debian Security Information: DSA-4751 (Google Search)
https://www.debian.org/security/2020/dsa-4751
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BMTFLVB7GLRF2CKGFPZ4G4R5DIIPHWI3/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BE6FKUN7IGTIR2MEEMWYDT7N5EJJLZI2/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HJJDI7JQFGQLVNCKMVY64LAFMKERAOK7/
http://www.squid-cache.org/Versions/v4/changesets/SQUID-2020_9.patch
https://github.com/squid-cache/squid/security/advisories/GHSA-vvj7-xjgq-g2jg
https://lists.debian.org/debian-lts-announce/2020/10/msg00005.html
SuSE Security Announcement: openSUSE-SU-2020:1346 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00012.html
SuSE Security Announcement: openSUSE-SU-2020:1369 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00017.html
https://usn.ubuntu.com/4477-1/
https://usn.ubuntu.com/4551-1/
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.