USN-6857-1
Dashboard / Vulnerabilities / USN-6857-1
USN-6857-1
Summary: squid3 vulnerabilities
Details: Joshua Rogers discovered that Squid incorrectly handled requests with the urn: scheme. A remote attacker could possibly use this issue to cause Squid to consume resources, leading to a denial of service. This issue only affected Ubuntu 16.04 LTS. (CVE-2021-28651) It was discovered that Squid incorrectly handled SSPI and SMB authentication. A remote attacker could use this issue to cause Squid to crash, resulting in a denial of service, or possibly obtain sensitive information. This issue only affected Ubuntu 16.04 LTS. (CVE-2022-41318) Joshua Rogers discovered that Squid incorrectly handled HTTP message processing. A remote attacker could possibly use this issue to cause Squid to crash, resulting in a denial of service. (CVE-2023-49285) Joshua Rogers discovered that Squid incorrectly handled Helper process management. A remote attacker could possibly use this issue to cause Squid to crash, resulting in a denial of service. (CVE-2023-49286) Joshua Rogers discovered that Squid incorrectly handled HTTP request parsing. A remote attacker could possibly use this issue to cause Squid to crash, resulting in a denial of service. (CVE-2023-50269, CVE-2024-25617)
References: https://ubuntu.com/security/notices/USN-6857-1, https://ubuntu.com/security/CVE-2021-28651, https://ubuntu.com/security/CVE-2022-41318, https://ubuntu.com/security/CVE-2023-49285, https://ubuntu.com/security/CVE-2023-49286, https://ubuntu.com/security/CVE-2023-50269, https://ubuntu.com/security/CVE-2024-25617
Affected packages
Package
Name: squid3
Purl: pkg:deb/ubuntu/squid3?arch=source&distro=esm-infra%2Fxenial
Affected ranges
Type: ECOSYSTEM
Events:
