CVE-2023-46724
Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.05%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This bug is fixed in Squid version 6.4. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. Those who you use a prepackaged version of Squid should refer to the package vendor for availability information on updated packages.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 4.05% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125, CWE-129, CWE-786, CWE-823, CWE-1285, CWE-295
- Affected
- squid-cache/squid
- Source
- security-advisories@github.com
References
- http://www.squid-cache.org/Versions/v5/SQUID-2023_4.patchMailing List, Patch
- http://www.squid-cache.org/Versions/v6/SQUID-2023_4.patchMailing List, Patch
- https://github.com/squid-cache/squid/commit/b70f864940225dfe69f9f653f948e787f99c3810Patch
- https://github.com/squid-cache/squid/security/advisories/GHSA-73m6-jm96-c6r3Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/A5QASTMCUSUEW3UOMKHZJB3FTONWSRXS/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MEV66D3PAAY6K7TWDT3WZBLCPLASFJDC/
- https://security.netapp.com/advisory/ntap-20231208-0001/
- http://www.squid-cache.org/Versions/v5/SQUID-2023_4.patchMailing List, Patch
- http://www.squid-cache.org/Versions/v6/SQUID-2023_4.patchMailing List, Patch
- https://github.com/squid-cache/squid/commit/b70f864940225dfe69f9f653f948e787f99c3810Patch
- https://github.com/squid-cache/squid/security/advisories/GHSA-73m6-jm96-c6r3Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/A5QASTMCUSUEW3UOMKHZJB3FTONWSRXS/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MEV66D3PAAY6K7TWDT3WZBLCPLASFJDC/
- https://security.netapp.com/advisory/ntap-20231208-0001/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.