Squid: denial of service in http digest authentication
Summary
| CVE | CVE-2023-46847 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-11-03 08:15:08 UTC |
| Updated | 2026-08-07 02:16:30 UTC |
| Description | Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS: 0.883510000 probability, percentile 0.997560000 (date 2026-08-10)
Problem Types: CWE-120 | CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | [email protected] | Secondary | 8.6 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H |
| 3.1 | CNA | CVSS | 8.6 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Redhat | Enterprise Linux | 8.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 9.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Eus | 8.6 | All | All | All |
| Operating System | Redhat | Enterprise Linux Eus | 8.8 | All | All | All |
| Operating System | Redhat | Enterprise Linux Eus | 9.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Eus | 9.2 | All | All | All |
| Operating System | Redhat | Enterprise Linux For Arm 64 | 8.0_aarch64 | All | All | All |
| Operating System | Redhat | Enterprise Linux For Ibm Z Systems | 8.0_s390x | All | All | All |
| Operating System | Redhat | Enterprise Linux For Power Little Endian | 8.0_ppc64le | All | All | All |
| Operating System | Redhat | Enterprise Linux Server | 7.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Aus | 8.2 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Aus | 8.4 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Aus | 8.6 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Aus | 9.2 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Tus | 8.2 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Tus | 8.4 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Tus | 8.6 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Tus | 8.8 | All | All | All |
| Operating System | Redhat | Enterprise Linux Server Tus | 9.2 | All | All | All |
| Operating System | Redhat | Enterprise Linux Workstation | 7.0 | All | All | All |
| Application | Squid-cache | Squid | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Red Hat | Red Hat Enterprise Linux 6 Extended Lifecycle Support | unaffected 7:3.4.14-15.el6_10.1 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 6 Extended Lifecycle Support | unaffected 7:3.1.23-24.el6_10.1 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 7 | unaffected 7:3.5.20-17.el7_9.9 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 7.6 Advanced Update Support | unaffected 7:3.5.20-12.el7_6.2 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 7.7 Advanced Update Support | unaffected 7:3.5.20-13.el7_7.1 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8 | unaffected 8080020231030214932.63b34585 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8 | unaffected 8090020231030224841.a75119d5 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.1 Update Services For SAP Solutions | unaffected 8010020231101141358.c27ad7f8 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.2 Advanced Update Support | unaffected 8020020231101135052.4cda2c84 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.2 Telecommunications Update Service | unaffected 8020020231101135052.4cda2c84 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.2 Update Services For SAP Solutions | unaffected 8020020231101135052.4cda2c84 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | unaffected 8040020231101101624.522a0ee4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.4 Telecommunications Update Service | unaffected 8040020231101101624.522a0ee4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.4 Update Services For SAP Solutions | unaffected 8040020231101101624.522a0ee4 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support | unaffected 8060020231031165747.ad008a3a * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9 | unaffected 7:5.5-5.el9_2.1 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9 | unaffected 7:5.5-6.el9_3.1 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9.0 Extended Update Support | unaffected 7:5.2-1.el9_0.3 * rpm | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| lists.debian.org/debian-lts-announce/2024/01/msg00003.html | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | |
| cve-details | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| 2245916 – (CVE-2023-46847) CVE-2023-46847 squid: Denial of Service in HTTP Digest Authentication | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| access.redhat.com/errata/RHSA-2023:7576 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2023:7578 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| security.netapp.com/advisory/ntap-20231130-0002 | af854a3a-2127-422b-91ae-364da2661108 | security.netapp.com | |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| SQUID-2023:3 Denial of Service in HTTP Digest Authentication · Advisory · squid-cache/squid · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Vendor Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2023-10-24T00:00:00.000Z | Reported to Red Hat. |
| CNA | 2023-10-19T00:00:00.000Z | Made public. |
Legacy QID Mappings
- 161045 Oracle Enterprise Linux Security Update for squid (ELSA-2023-6266)
- 161050 Oracle Enterprise Linux Security Update for squid:4 (ELSA-2023-6267)
- 161052 Oracle Enterprise Linux Security Update for squid (ELSA-2023-6805)
- 161091 Oracle Enterprise Linux Security Update for squid (ELSA-2023-6748)
- 161191 Oracle Enterprise Linux Security Update for squid:4 (ELSA-2023-7213)
- 161285 Oracle Enterprise Linux Security Update for squid34 (ELSA-2023-6882)
- 161286 Oracle Enterprise Linux Security Update for squid (ELSA-2023-6884)
- 199932 Ubuntu Security Notification for Squid Vulnerabilities (USN-6500-1)
- 199990 Ubuntu Security Notification for Squid Vulnerabilities (USN-6500-2)
- 242271 Red Hat Update for squid (RHSA-2023:6266)
- 242272 Red Hat Update for squid:4 (RHSA-2023:6267)
- 242276 Red Hat Update for squid (RHSA-2023:6268)
- 242289 Red Hat Update for squid (RHSA-2023:6748)
- 242337 Red Hat Update for squid:4 (RHSA-2023:6803)
- 242339 Red Hat Update for squid:4 (RHSA-2023:6804)
- 242382 Red Hat Update for squid:4 (RHSA-2023:6810)
- 242389 Red Hat Update for squid:4 (RHSA-2023:6801)
- 242390 Red Hat Update for squid (RHSA-2023:6805)
- 242439 Red Hat Update for squid:4 (RHSA-2023:7213)
- 257262 Centos Security Update for squid
- 257292 CentOS Security Update for squid (CESA-2023:6805)
- 296108 Oracle Solaris 11.4 Support Repository Update (SRU) 66.164.1 Missing (CPUJAN2024)
- 356512 Amazon Linux Security Advisory for squid : ALAS2023-2023-402
- 356552 Amazon Linux Security Advisory for squid : ALAS-2023-1872
- 356984 Amazon Linux Security Advisory for squid : AL2012-2023-468
- 379040 Alibaba Cloud Linux Security Update for squid (ALINUX2-SA-2023:0045)
- 379044 Alibaba Cloud Linux Security Update for squid:4 (ALINUX3-SA-2023:0135)
- 505941 Alpine Linux Security Update for squid
- 6000513 Debian Security Update for squid (DSA 5637-1)
- 755236 SUSE Enterprise Linux Security Update for squid (SUSE-SU-2023:4381-1)
- 755237 SUSE Enterprise Linux Security Update for squid (SUSE-SU-2023:4380-1)
- 755241 SUSE Enterprise Linux Security Update for squid (SUSE-SU-2023:4384-1)
- 941335 AlmaLinux Security Update for squid (ALSA-2023:6266)
- 941342 AlmaLinux Security Update for squid:4 (ALSA-2023:6267)
- 941397 AlmaLinux Security Update for squid (ALSA-2023:6748)
- 941468 AlmaLinux Security Update for squid:4 (ALSA-2023:7213)
- 961066 Rocky Linux Security Update for squid:4 (RLSA-2023:6267)
- 961070 Rocky Linux Security Update for squid (RLSA-2023:6266)
- 961075 Rocky Linux Security Update for squid:4 (RLSA-2023:7213)