OESA-2023-1776

    Dashboard / Vulnerabilities / OESA-2023-1776

    OESA-2023-1776

    Published: 3 Nov 2023Last Modified: 18 Aug 2026

    Summary: squid security update

    Details: Squid is a high-performance proxy caching server. It handles all requests in a single, non-blocking, I/O-driven process and keeps meta data and implements negative caching of failed requests. Security Fix(es): Description: Due to chunked decoder lenience Squid is vulnerable to Request/Response smuggling attacks when parsing HTTP/1.1 and ICAP messages Reference: https://github.com/squid-cache/squid/security/advisories/GHSA-j83v-w3p4-5cqh Affected versions: 2.6-6.3. Patched in 6.4.(CVE-2023-46846) Description: Due to a buffer overflow bug Squid is vulnerable to a Denial of Service attack against HTTP Digest Authentication Reference: https://github.com/squid-cache/squid/security/advisories/GHSA-phqj-m8gv-cq4g Affected versions: 3.2.0.1-5.9, 6.0-6.3(CVE-2023-46847)

    Affected packages

    Package

    Name: squid

    Purl: pkg:rpm/openEuler/squid&distro=openEuler-20.03-LTS-SP1

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -4.9-14.oe1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    OESA-2023-1776 | CVE-DB