CVE-2023-46728

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of Service attack against Squid's Gopher gateway. The gopher protocol is always available and enabled in Squid prior to Squid 6.0.1. Responses triggering this bug are possible to be received from any gopher server, even those without malicious intent. Gopher support has been removed in Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should reject all gopher URL requests.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
GitHub_MCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
VendorProductVersion
squid-cachesquid
𝑥
< 6.0.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
squid
bullseye (security)
vulnerable
bullseye
ignored
bookworm
ignored
buster
ignored
bookworm (security)
vulnerable
sid
6.12-1
fixed
trixie
6.12-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
squid
mantic
not-affected
lunar
Fixed 5.7-1ubuntu3.1
released
jammy
Fixed 5.7-0ubuntu0.22.04.2
released
focal
Fixed 4.10-1ubuntu1.8
released
bionic
ignored
xenial
ignored
trusty
ignored
squid3
mantic
dne
lunar
dne
jammy
dne
focal
dne
bionic
Fixed 3.5.27-1ubuntu1.14+esm1
released
xenial
Fixed 3.5.12-1ubuntu7.16+esm2
released
trusty
ignored