5.3
CVSSv3

CVE-2023-46846

Published: 03/11/2023 Updated: 21/11/2024

Vulnerability Summary

SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote malicious user to perform Request/Response smuggling past firewall and frontend security systems.

Vulnerable Product Search on Vulmon Subscribe to Product

squid-cache squid

redhat enterprise linux 8.0

redhat enterprise linux 9.0

redhat enterprise linux eus 8.6

redhat enterprise linux eus 8.8

redhat enterprise linux eus 9.0

redhat enterprise linux eus 9.2

redhat enterprise linux for arm 64 8.0 aarch64

redhat enterprise linux for ibm z systems 8.0 s390x

redhat enterprise linux for power little endian 8.0 ppc64le

redhat enterprise linux server aus 8.2

redhat enterprise linux server aus 8.4

redhat enterprise linux server aus 8.6

redhat enterprise linux server aus 9.2

redhat enterprise linux server tus 8.2

redhat enterprise linux server tus 8.4

redhat enterprise linux server tus 8.6

redhat enterprise linux server tus 8.8

redhat enterprise linux server tus 9.2

Vendor Advisories

Synopsis Critical: squid security update Type/Severity Security Advisory: Critical Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for squid is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as having a securi ...
Synopsis Critical: squid:4 security update Type/Severity Security Advisory: Critical Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the squid:4 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as ...
Synopsis Critical: squid:4 security update Type/Severity Security Advisory: Critical Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the squid:4 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as ...
Synopsis Critical: squid security update Type/Severity Security Advisory: Critical Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for squid is now available for Red Hat Enterprise Linux 90 Extended Update SupportRed Hat Product Security has rated this ...
Synopsis Critical: squid security update Type / Sévérité Security Advisory: Critical Analyse des correctifs dans Red Hat Insights Identifiez et remédiez aux systèmes concernés par cette alerte Voir les systèmes concernés Sujet An update for squid is now available for Red Hat Enterprise Linux 9Red Hat Product Security has r ...
A flaw was found in squid When Squid is parsing ESI, it keeps the ESI elements in ESIContext ESIContext contains a buffer for holding a stack of ESIElements When a new ESIElement is parsed, it is added via addStackElement addStackElement has a check for the number of elements in this buffer, but it's off by 1, leading to a Heap Overflow of 1 el ...
Due to chunked decoder lenience Squid is vulnerable to Request/Response smuggling attacks when parsing HTTP/11 and ICAP messages (CVE-2023-46846) ...