UBUNTU-CVE-2020-24606
Dashboard / Vulnerabilities / UBUNTU-CVE-2020-24606
UBUNTU-CVE-2020-24606
Summary:
Details: Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only occurs when cache_peer is used with the cache digests feature. The problem exists because peerDigestHandleReply() livelocking in peer_digest.cc mishandles EOF.
References: https://ubuntu.com/security/CVE-2020-24606, https://github.com/squid-cache/squid/security/advisories/GHSA-vvj7-xjgq-g2jg, https://ubuntu.com/security/notices/USN-4477-1, https://ubuntu.com/security/notices/USN-4551-1, https://www.cve.org/CVERecord?id=CVE-2020-24606
Affected packages
Package
Name: squid3
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
