发布时间: 2023年12月15日
修改时间: 2024年10月31日
Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.
NVD | openEuler | |
---|---|---|
Confidentiality | None | None |
Attack Vector | Network | Network |
CVSS评分 | 7.5 | 8.6 |
Attack Complexity | Low | Low |
Privileges Required | None | None |
Scope | Unchanged | Changed |
Integrity | None | None |
User Interaction | None | None |
Availability | High | High |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2023-1822 | squid security update | 2023年12月15日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-4A | squid | Fixed |
KY3.4-5 | squid | Fixed |
KY3.5.1 | squid | Fixed |
KY3.5.2 | squid | Fixed |