CVE-2023-49285

HIGH

squid < 6.4 - Denial of Service via HTTP Message Processing Buffer Overread

Title source: llm
STIX 2.1

Description

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Scores

CVSS v3 8.6
EPSS 0.8882
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Details

CWE
CWE-125 CWE-126
Status published
Products (1)
squid-cache/squid < 6.4
Published Dec 04, 2023
Tracked Since Feb 18, 2026