CVE-2020-24606
CVE-2020-24606
Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only occurs when cache_peer is used with the cache digests feature. The problem exists because peerDigestHandleReply() livelocking in peer_digest.cc mishandles EOF.
CVSS:3.1/AC:L/AV:N/A:H/C:N/I:N/PR:N/S:C/UI:N
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00017.htmlhttps://github.com/squid-cache/squid/security/advisories/GHSA-vvj7-xjgq-g2jghttps://lists.debian.org/debian-lts-announce/2020/10/msg00005.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BE6FKUN7IGTIR2MEEMWYDT7N5EJJLZI2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BMTFLVB7GLRF2CKGFPZ4G4R5DIIPHWI3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HJJDI7JQFGQLVNCKMVY64LAFMKERAOK7/https://security.netapp.com/advisory/ntap-20210219-0007/https://security.netapp.com/advisory/ntap-20210226-0006/https://security.netapp.com/advisory/ntap-20210226-0007/https://usn.ubuntu.com/4477-1/https://usn.ubuntu.com/4551-1/