squid: CVE-2023-46847: SQUID-2023:3 Denial of Service in HTTP Digest Authentication

Related Vulnerabilities: CVE-2023-46847  

Debian Bug report logs - #1055250
squid: CVE-2023-46847: SQUID-2023:3 Denial of Service in HTTP Digest Authentication

version graph

Package: squid; Maintainer for squid is Luigi Gangitano <luigi@debian.org>; Source for squid is src:squid (PTS, buildd, popcon).

Reported by: Andras Korn <korn-debbugs@elan.rulez.org>

Date: Wed, 25 Oct 2023 10:39:02 UTC

Severity: grave

Tags: patch, security, upstream

Found in version squid/6.3-1

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, Luigi Gangitano <luigi@debian.org>:
Bug#1054537; Package squid. (Wed, 25 Oct 2023 10:39:04 GMT) (full text, mbox, link).


Acknowledgement sent to Andras Korn <korn-debbugs@elan.rulez.org>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, Luigi Gangitano <luigi@debian.org>. (Wed, 25 Oct 2023 10:39:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Andras Korn <korn-debbugs@elan.rulez.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: Squid 6.3: multiple vulnerabilities, patches available
Date: Wed, 25 Oct 2023 12:37:40 +0200
Package: squid
Version: 6.3-1
Severity: grave
Tags: security patch
X-Debbugs-Cc: Debian Security Team <team@security.debian.org>

Hi,

https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-2725 links to a bunch of squid advisories, three of which have CVSS scores of 9+:

https://github.com/squid-cache/squid/security/advisories/GHSA-2g3c-pg7q-g59w
https://github.com/squid-cache/squid/security/advisories/GHSA-phqj-m8gv-cq4g
https://github.com/squid-cache/squid/security/advisories/GHSA-543m-w2m2-g255
https://github.com/squid-cache/squid/security/advisories/GHSA-j83v-w3p4-5cqh

Squid 6.4 includes the fix; patches for 6.3 are provided, but don't apply cleanly to the Debian sources.

Please package a non-vulnerable version ASAP.

Thanks!

András

-- System Information:
Debian Release: trixie/sid
  APT prefers unstable
  APT policy: (350, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Init: runit (via /run/runit.stopit)
LSM: AppArmor: enabled

-- 
           Computers are not intelligent. They only think they are.



Added tag(s) upstream. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Thu, 26 Oct 2023 04:33:03 GMT) (full text, mbox, link).


Bug 1054537 cloned as bugs 1055249, 1055250, 1055251 Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Thu, 02 Nov 2023 20:09:04 GMT) (full text, mbox, link).


Changed Bug title to 'squid: CVE-2023-46847: SQUID-2023:3 Denial of Service in HTTP Digest Authentication' from 'Squid 6.3: multiple vulnerabilities, patches available'. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Thu, 02 Nov 2023 20:09:05 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Fri Nov 3 17:55:29 2023; Machine Name: bembo

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.