CVE-2023-50269
14.12.2023, 18:15
Squid is a caching proxy for the Web. Due to an Uncontrolled Recursion bug in versions 2.6 through 2.7.STABLE9, versions 3.1 through 5.9, and versions 6.0.1 through 6.5, Squid may be vulnerable to a Denial of Service attack against HTTP Request parsing. This problem allows a remote client to perform Denial of Service attack by sending a large X-Forwarded-For header when the follow_x_forwarded_for feature is configured. This bug is fixed by Squid version 6.6. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives.Enginsight
Vendor | Product | Version |
---|---|---|
squid-cache | squid | 3.1 ≤ 𝑥 ≤ 5.9 |
squid-cache | squid | 6.0.1 ≤ 𝑥 ≤ 6.5 |
squid-cache | squid | 2.6 |
squid-cache | squid | 2.7 |
squid-cache | squid | 2.7:stable1 |
squid-cache | squid | 2.7:stable2 |
squid-cache | squid | 2.7:stable3 |
squid-cache | squid | 2.7:stable4 |
squid-cache | squid | 2.7:stable5 |
squid-cache | squid | 2.7:stable6 |
squid-cache | squid | 2.7:stable7 |
squid-cache | squid | 2.7:stable8 |
squid-cache | squid | 2.7:stable9 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
squid |
| ||||||||||||||||
squid3 |
|
Common Weakness Enumeration
References