← back
CVE-2023-46848highCWE-681

Squid: denial of service in ftp

26Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.6epss 10%
exploitation probability
10%top 4% of all CVEs
observed exploitation
nono source reports it
In short

Squid proxy can be forced to crash or stop responding when someone sends specially crafted FTP requests through HTTP. This allows attackers to disrupt service for all users relying on that proxy.

Technical detail

Squid is vulnerable to DoS via malformed ftp:// URLs processed through HTTP request messages or derived from FTP Native protocol input. The vulnerability allows remote attackers without authentication to trigger resource exhaustion or crash conditions by manipulating URL parsing logic, impacting availability for all downstream clients.

Summary generated and translated by AI from the official description.
Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs from FTP Native input.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H