Multiple buffer overflows in squidGuard 1.4 allow remote attackers to bypass intended URL blocking via a long URL, related to (1) the relationship between a certain buffer size in squidGuard and a certain buffer size in Squid and (2) a redirect URL that contains information about the originally requested URL.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade squidguard | Jul 30, 2024 | Oct 28, 2009 |
| Freebsd | — | Upgrade squidGuard | Dec 10, 2025 | Oct 22, 2009 |
| Suse | — | Upgrade squidGuard-docUpgrade squidGuard | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade squidguard | Nov 19, 2024 | Oct 28, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub