Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.
{
"cwe_ids": [
"CWE-126"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/49xxx/CVE-2023-49285.json",
"cna_assigner": "GitHub_M"
}[
{
"target": {
"file": "src/mem/old_api.cc"
},
"source": "https://github.com/squid-cache/squid/commit/03c8a93e863f873b5d6ff45adb786db447cabcd6",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"257044594987088765650398720630223476415",
"67402589260379821383315680181466566587",
"331359421529674039643518234169489425487",
"317681953838762131340943365743079298223"
]
},
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2023-49285-a5731322"
},
{
"target": {
"function": "memConfigure",
"file": "src/mem/old_api.cc"
},
"source": "https://github.com/squid-cache/squid/commit/03c8a93e863f873b5d6ff45adb786db447cabcd6",
"deprecated": false,
"digest": {
"length": 404.0,
"function_hash": "286476429438028643895733673882440714010"
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2023-49285-ac80c167"
}
]
"2026-04-13T11:57:13Z"
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-49285.json"