Buffer overflow in sgLog.c in squidGuard 1.3 and 1.4 allows remote attackers to cause a denial of service (application hang or loss of blocking functionality) via a long URL with many / (slash) characters, related to "emergency mode."
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade squidguard | Jul 30, 2024 | Oct 28, 2009 |
| Freebsd | — | Upgrade squidGuard | Dec 10, 2025 | Oct 22, 2009 |
| Suse | — | Upgrade squidGuardUpgrade squidGuard-doc | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade squidguard | Nov 19, 2024 | Oct 28, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub