UBUNTU-CVE-2023-46847
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-46847
UBUNTU-CVE-2023-46847
Summary:
Details: Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.
References: https://ubuntu.com/security/CVE-2023-46847, https://github.com/squid-cache/squid/security/advisories/GHSA-phqj-m8gv-cq4g, https://lists.squid-cache.org/pipermail/squid-announce/2023-October/000154.html, https://megamansec.github.io/Squid-Security-Audit/digest-overflow.html, https://ubuntu.com/security/notices/USN-6500-1, https://ubuntu.com/security/notices/USN-6500-2, https://www.cve.org/CVERecord?id=CVE-2023-46847
Affected packages
Package
Name: squid3
Purl: pkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-infra/xenial
Affected ranges
Type: ECOSYSTEM
Events:
