A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the worker process when a large header is retrieved from the disk cache, resulting in a denial of service.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-4312-1 squid security update
Debian DSA Debian DSA DSA-5982-1 squid security update
EUVD EUVD EUVD-2023-58107 A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the worker process when a large header is retrieved from the disk cache, resulting in a denial of service.
Ubuntu USN Ubuntu USN USN-6728-1 Squid vulnerabilities
Ubuntu USN Ubuntu USN USN-6728-3 Squid vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

Disabling the disk caching mechanism will mitigate this vulnerability. To achieve this, remove all the 'cache_dir' directives from the Squid configuration, typically in the /etc/squid/squid.conf file.

History

Fri, 22 Nov 2024 12:00:00 +0000

Type Values Removed Values Added
References

Thu, 24 Oct 2024 18:00:00 +0000

Type Values Removed Values Added
Description Squid is vulnerable to Denial of Service attack against HTTP and HTTPS clients due to an Improper Handling of Structural Elements bug. A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the worker process when a large header is retrieved from the disk cache, resulting in a denial of service.

Mon, 16 Sep 2024 16:30:00 +0000

Type Values Removed Values Added
References

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-09-12T19:50:57.435Z

Reserved: 2023-10-27T09:37:47.593Z

Link: CVE-2023-5824

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-11-03T08:15:08.270

Modified: 2024-11-21T08:42:34.053

Link: CVE-2023-5824

cve-icon Redhat

Severity : Important

Publid Date: 2023-10-19T00:00:00Z

Links: CVE-2023-5824 - Bugzilla

cve-icon OpenCVE Enrichment

No data.