UBUNTU-CVE-2023-5824
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-5824
UBUNTU-CVE-2023-5824
Summary:
Details: A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the worker process when a large header is retrieved from the disk cache, resulting in a denial of service.
References: https://ubuntu.com/security/CVE-2023-5824, https://github.com/squid-cache/squid/security/advisories/GHSA-543m-w2m2-g255, https://lists.squid-cache.org/pipermail/squid-announce/2023-October/000155.html, https://megamansec.github.io/Squid-Security-Audit/cache-headers.html, https://ubuntu.com/security/notices/USN-6728-1, https://ubuntu.com/security/notices/USN-6728-2, https://www.cve.org/CVERecord?id=CVE-2023-5824, https://ubuntu.com/security/notices/USN-6728-3
Affected packages
Package
Name: squid3
Purl: pkg:deb/ubuntu/[email protected]+esm6?arch=source&distro=esm-infra/xenial
Affected ranges
Type: ECOSYSTEM
Events:
