VDB
BDU%3A2023-07920
BDU%3A2023-07920
PUBLISHED
CVSS 8.600000381469727 HIGH
Уязвимость обработчика аутентификации HTTP Digest Authentication прокси-сервера Squid, позволяющая нарушителю вызвать отказ в обслуживании или оказать иное воздействие
Risk Scores
CVSS 3.1
8.600000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Enterprise Linux 9.0 Extended Update Support | 7:5.2-1.el9_0.3 |
| Red Hat | Red Hat Enterprise Linux 6 Extended Lifecycle Support | 7:3.1.23-24.el6_10.1 |
| Red Hat | Red Hat Enterprise Linux 8 | 8090020231030224841.a75119d5, 8080020231030214932.63b34585 |
| Red Hat | Red Hat Enterprise Linux 7.7 Advanced Update Support | 7:3.5.20-13.el7_7.1 |
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support | 8060020231031165747.ad008a3a |
| Red Hat | Red Hat Enterprise Linux 9 | 7:5.5-5.el9_2.1, 7:5.5-6.el9_3.1 |
| Red Hat | Red Hat Enterprise Linux 8.2 Advanced Update Support | 8020020231101135052.4cda2c84 |
| Novell Inc., Red Hat Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», ООО «РусБИТех-Астра», АО «ИВК», АО «НТЦ ИТ РОСА», Squid Software Foundation, АО "НППКТ" | SUSE Linux Enterprise Server for SAP Applications, Suse Linux Enterprise Server, Red Hat Enterprise Linux, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), Astra Linux Special Edition (запись в едином реестре российских программ №369), Альт 8 СП (запись в едином реестре российских программ №4305), Astra Linux Common Edition (запись в едином реестре российских программ №4433), РОСА ХРОМ (запись в едином реестре российских программ №1607), Squid, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913) | |
| Red Hat | Red Hat Enterprise Linux 6 Extended Lifecycle Support | 7:3.4.14-15.el6_10.1 |
| 3.2.0.1 | ||
| Red Hat | Red Hat Enterprise Linux 8.4 Telecommunications Update Service | 8040020231101101624.522a0ee4 |
| Red Hat | Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | 8040020231101101624.522a0ee4 |
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | 8040020231101101624.522a0ee4 |
| Red Hat | Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | 8010020231101141358.c27ad7f8 |
| Red Hat | Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | 8020020231101135052.4cda2c84 |
| Red Hat | Red Hat Enterprise Linux 7.6 Advanced Update Support(Disable again in 2026 - SPRHEL-7118) | 7:3.5.20-12.el7_6.2 |
| Red Hat | Red Hat Enterprise Linux 7 | 7:3.5.20-17.el7_9.9 |
| Red Hat | Red Hat Enterprise Linux 8.2 Telecommunications Update Service | 8020020231101135052.4cda2c84 |
Timeline
- Nov 3, 2023 CVE Published
- Nov 23, 2023 PoC Published
- Sep 1, 2025 PoC Published
- Jan 20, 2026 CVE Updated
- May 18, 2026 Distribution Patch
- May 18, 2026 Distribution Patch
- May 18, 2026 Distribution Patch
- May 18, 2026 Distribution Patch
- May 18, 2026 Distribution Patch
- May 18, 2026 Distribution Patch
- May 18, 2026 Distribution Patch
- May 18, 2026 Distribution Patch
References
- https://security-tracker.debian.org/tracker/CVE-2023-46847 url
- https://github.com/squid-cache/squid/security/advisories/GHSA-phqj-m8gv-cq4g url
- https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/2.10/ url
- https://abf.rosa.ru/advisories/ROSA-SA-2024-2477 url
- https://access.redhat.com/security/cve/cve-2023-46847 advisory
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2024-1031SE47 advisory
- RHSA-2023:6266 vendor-advisory
- RHSA-2023:6267 vendor-advisory
- RHSA-2023:6268 vendor-advisory
- RHSA-2023:6801 vendor-advisory
- RHSA-2023:6803 vendor-advisory
- RHSA-2023:6804 vendor-advisory
- RHSA-2023:6805 vendor-advisory
- RHSA-2023:6810 vendor-advisory
- RHSA-2023:6884 vendor-advisory
- RHSA-2023:7578 vendor-advisory
- https://access.redhat.com/security/cve/CVE-2023-46847 vdb
- RHSA-2023:6748 vendor-advisory
- RHSA-2023:6882 vendor-advisory
- RHSA-2023:7213 vendor-advisory
…and 9 more