← All CVEs

CVE-2023-49285

high · 8.6

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

8.6
CVSS
88.1%
EPSS (exploit prob.)
100th
EPSS percentile
2023-12-04
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Weaknesses

CWE-126CWE-125

Affected products

VendorProductAffected versions
squid-cachesquid<= 6.4

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-49285