Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using --with-openssl
are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This bug is fixed in Squid version 6.4. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. Those who you use a prepackaged version of Squid should refer to the package vendor for availability information on updated packages.
{ "vanir_signatures": [ { "target": { "function": "matchDomainName", "file": "src/anyp/Uri.cc" }, "id": "CVE-2023-46724-2913b03e", "source": "https://github.com/squid-cache/squid/commit/b70f864940225dfe69f9f653f948e787f99c3810", "digest": { "length": 944.0, "function_hash": "210215246844197458567831775363745291472" }, "signature_version": "v1", "deprecated": false, "signature_type": "Function" }, { "target": { "file": "src/anyp/Uri.cc" }, "id": "CVE-2023-46724-6184ef0f", "source": "https://github.com/squid-cache/squid/commit/b70f864940225dfe69f9f653f948e787f99c3810", "digest": { "line_hashes": [ "132297003046321410898293712443124375497", "141294028970175884415189950830511831259", "83365289692056968680299252530166654273", "263561776175962430572252611013012687107", "163679156619555015851941026236844524402", "182953648326232214989768464638856171680", "337849282034998695637314799915579350143" ], "threshold": 0.9 }, "signature_version": "v1", "deprecated": false, "signature_type": "Line" }, { "target": { "function": "urlInitialize", "file": "src/anyp/Uri.cc" }, "id": "CVE-2023-46724-c474f5d2", "source": "https://github.com/squid-cache/squid/commit/b70f864940225dfe69f9f653f948e787f99c3810", "digest": { "length": 1833.0, "function_hash": "5004815670061213126088965192724588639" }, "signature_version": "v1", "deprecated": false, "signature_type": "Function" } ] }