← back
CVE-2023-49286highCWE-253CWE-617

Denial of Service in Helper Process management

26Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.6epss 10%
exploitation probability
10%top 5% of all CVEs
observed exploitation
nono source reports it
In short

Squid proxy has a bug where it doesn't properly check if helper processes are working correctly, allowing attackers to crash the helper management system and make the proxy stop serving requests.

Technical detail

An incorrect validation of function return values in Squid's helper process management allows remote attackers to trigger a denial of service condition by exploiting the failure to properly handle error states, resulting in service disruption. Affected versions prior to 6.5; no authentication or special privileges required for exploitation.

Summary generated and translated by AI from the official description.
Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Incorrect Check of Function Return Value bug Squid is vulnerable to a Denial of Service attack against its Helper process management. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Affected products
squid-cache · squid