A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the worker process when a large header is retrieved from the disk cache, resulting in a denial of service.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4312-1 | squid security update |
Debian DSA |
DSA-5982-1 | squid security update |
EUVD |
EUVD-2023-58107 | A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the worker process when a large header is retrieved from the disk cache, resulting in a denial of service. |
Ubuntu USN |
USN-6728-1 | Squid vulnerabilities |
Ubuntu USN |
USN-6728-3 | Squid vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
Disabling the disk caching mechanism will mitigate this vulnerability. To achieve this, remove all the 'cache_dir' directives from the Squid configuration, typically in the /etc/squid/squid.conf file.
References
History
Mon, 03 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 24 Oct 2024 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Squid is vulnerable to Denial of Service attack against HTTP and HTTPS clients due to an Improper Handling of Structural Elements bug. | A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the worker process when a large header is retrieved from the disk cache, resulting in a denial of service. |
Mon, 16 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-06T20:51:27.614Z
Reserved: 2023-10-27T09:37:47.593Z
Link: CVE-2023-5824
No data.
Status : Modified
Published: 2023-11-03T08:15:08.270
Modified: 2025-11-03T19:15:42.437
Link: CVE-2023-5824
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN