← back
CVE-2023-46728highCWE-476

SQUID-2021:8 Denial of Service in Gopher gateway

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 6.0%
exploitation probability
6.0%top 7% of all CVEs
observed exploitation
nono source reports it
In short

Squid proxy has a bug in its Gopher gateway that can crash the service when receiving certain responses, even from legitimate servers. This causes a denial of service where the proxy stops working for all users.

Technical detail

A NULL pointer dereference in Squid's Gopher protocol handler allows remote attackers to trigger a denial of service by sending specially crafted responses. The Gopher gateway is enabled by default in versions prior to 6.0.1, and exploitation requires only network access to a Gopher server.

Summary generated and translated by AI from the official description.
Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of Service attack against Squid's Gopher gateway. The gopher protocol is always available and enabled in Squid prior to Squid 6.0.1. Responses triggering this bug are possible to be received from any gopher server, even those without malicious intent. Gopher support has been removed in Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should reject all gopher URL requests.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
squid-cache · squid