Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Incorrect Check of Function Return Value bug Squid is vulnerable to a Denial of Service attack against its Helper process management. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.
{
"cwe_ids": [
"CWE-253",
"CWE-617"
]
}[
{
"id": "CVE-2023-49286-a5731322",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"line_hashes": [
"257044594987088765650398720630223476415",
"67402589260379821383315680181466566587",
"331359421529674039643518234169489425487",
"317681953838762131340943365743079298223"
],
"threshold": 0.9
},
"target": {
"file": "src/mem/old_api.cc"
},
"source": "https://github.com/squid-cache/squid/commit/03c8a93e863f873b5d6ff45adb786db447cabcd6"
},
{
"id": "CVE-2023-49286-ac80c167",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"function_hash": "286476429438028643895733673882440714010",
"length": 404.0
},
"target": {
"file": "src/mem/old_api.cc",
"function": "memConfigure"
},
"source": "https://github.com/squid-cache/squid/commit/03c8a93e863f873b5d6ff45adb786db447cabcd6"
}
]