发布时间: 2024年8月30日
修改时间: 2024年9月27日
Squid is a web proxy cache. Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of Service attack against HTTP Chunked decoder due to an uncontrolled recursion bug. This problem allows a remote attacker to cause Denial of Service when sending a crafted, chunked, encoded HTTP Message. This bug is fixed in Squid version 6.8. In addition, patches addressing this problem for the stable releases can be found in Squid s patch archives. There is no workaround for this issue.
NVD | openEuler | |
---|---|---|
CVSS评分 | 8.6 | 8.6 |
Attack Vector | Network | Network |
Attack Complexity | Low | Low |
Privileges Required | None | None |
User Interaction | None | None |
Scope | Changed | Changed |
Confidentiality | None | None |
Integrity | None | None |
Availability | High | High |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2024-3843 | squid security update | 2024年9月27日 |
KylinSec-SA-2024-4032 | squid security update | 2024年9月27日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-5A | squid | Fixed |
KY3.5.2 | squid | Fixed |
V6 | squid | Fixed |