A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the worker process when a large header is retrieved from the disk cache, resulting in a denial of service.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libecapUpgrade libecap-develUpgrade squid | Nov 24, 2023 | Nov 3, 2023 |
| Alpine Linux | — | Upgrade squid | Mar 21, 2024 | Nov 3, 2023 |
| Amazon_linux_2023 | — | Upgrade squid-debugsourceUpgrade squid-debuginfoUpgrade squid | Feb 17, 2025 | Oct 19, 2023 |
| Centos_linux | — | Upgrade squid-debuginfoUpgrade libecap-develUpgrade squidUpgrade squid-debugsourceUpgrade libecap-debugsourceUpgrade libecap-debuginfoUpgrade libecap | Nov 23, 2023 | Nov 3, 2023 |
| Debian | — | Upgrade squid | May 15, 2025 | Nov 3, 2023 |
| Oracle_linux | — | Upgrade squidUpgrade libecapUpgrade libecap-devel | Nov 28, 2023 | Oct 19, 2023 |
| Redhat_linux | — | Upgrade libecap-debuginfoUpgrade libecap-develUpgrade squidUpgrade libecapUpgrade squid-debuginfoNo solution existsUpgrade libecap-debugsourceUpgrade squid-debugsource | Nov 23, 2023 | Nov 3, 2023 |
| Rocky_linux | — | Upgrade libecap-develUpgrade libecapUpgrade libecap-debugsourceUpgrade libecap-debuginfo | Aug 15, 2024 | Nov 3, 2023 |
| Ubuntu | — | Upgrade squid | Apr 11, 2024 | Nov 3, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Nov 3, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub