Back

HIGH

Squid: denial of service in http digest authentication

Published Nov 3, 2023

Description

Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (21)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 3, 2023
Updated Aug 7, 2026
Reserved Oct 27, 2023
NVD
Status Modified
Modified Aug 7, 2026
Red Hat
Severity Critical
Public date Oct 19, 2023